Dark Web Credentials for Sale: Rapid and Secure Recovery for a Higher Education Institution

Highlights

  • UK higher education institution supporting 150,000+ students and staff
  • 24×7 monitoring to secure recovery and sustain protection
  • Two weeks from dark web claim to evidence-backed findings
  • Emergency MDR and Clarity Extend

The challenge

A UK higher education institution was alerted by a third-party that legitimate account credentials had been compromised and were being advertised for sale on the dark web. Alongside this, there were claims that over 100TB of data had been impacted. The activity pattern strongly suggested the involvement of an Initial Access Broker (IAB), cybercriminals who gain a foothold in systems, often using stolen credentials or vulnerabilities and then sell that access on to other threat actors to conduct follow-on attacks.

This presented an urgent risk – once access is sold, attackers are able to move rapidly from credential abuse to cause deeper compromise, service disruption and large-scale data extortion.

With a large and complex infrastructure covering over 12,000 endpoints and the potential exposure of highly sensitive data and intellectual property (IP), the institution urgently needed clear, defensible answers. How was access gained? What actions did the attacker take once inside? Was any data viewed or exfiltrated? And were the threat actor’s claims credible?

Quorum Cyber was engaged to rapidly get to the truth, coordinate a secure eradication and recovery, and establish the foundations for robust, long-term protection against future attacks.

The approach

Quorum Cyber conducted the investigation along two parallel tracks. The Incident Response (IR) team worked within the environment to pinpoint the likely ingress route and reconstruct attacker activity, tracking signs of enumeration, privilege escalation, persistence mechanisms, and any attempted lateral movement.

At the same time, Threat Intelligence (TI) experts traced the origin of the dark web listing and examined the surrounding claims, building a clear picture of what was being marketed, how the access was presented, and what this revealed about the threat actor’s intent and potential next steps.

To turn hypotheses into evidence, we deployed a remote forensics and artefact collection capability across the impacted servers. This established a clear defensible timeline and determined what data had been accessed, providing clear, evidence-led answers for operational stakeholders and legal counsel.

During the eradication and recovery phase, Quorum Cyber deployed emergency Managed Detection and Response (MDR) to secure the estate. Backed by 24×7 monitoring and rapid response from its Security Operations Centre (SOC) team, this gave the organisation immediate visibility across the environment, transformed previously opaque areas into actionable insight, reduced risk, and restored confidence.

“When a dark web claim surfaced, we needed to move quickly without disrupting critical services,” said the Director of Information Security, UK Higher Education Institution. “Quorum Cyber helped us turn uncertainty into evidence and then manage the threat with 24×7 monitoring that gave us confidence to recover safely.”

Importantly, emergency MDR gave the university security team immediate reassurance. Their team could progress recovery activities with confidence, knowing suspicious behaviour would be identified, contained and communicated quickly, with no surprises. The goal was to move the organisation from its vulnerable state to a safe one, so it could recover from the cyber incident and return to normal operations as quickly and securely as possible.

Once the incident stabilised, this emergency MDR posture became a stepping stone to a long-term MDR service, with Clarity Extend, providing the team with visibility, monitoring, and response capability as ‘business as usual’, not just during a crisis. The Clarity user interface gave their team immediate visibility into their security posture and how it was being managed by Quorum Cyber.Top of Form

“Quorum Cyber’s Emergency MDR service helped us contain the immediate threat and bring stability back to the environment. Once we recovered, we knew we wanted that same visibility, proactive monitoring, and reassurance on an ongoing basis, which made a long-term partnership the right decision for us,” explained the institution’s Director of Information Security.

Results

Within two weeks, the institution was able to replace speculation with certainty; crucial in a higher education environment where trust, continuity, and duty of care matter as much as technical recovery. With their evidence-backed understanding of the initial access and attacker behaviour, the stakeholders were able to make confident decisions about containment, communications, and legal posture.

Through 24×7 SOC-led threat detection and response, Quorum Cyber guided the organisation through eradication and recovery while keeping day-to-day services running across their large, diverse estate.

Just as importantly, clear findings and targeted remediation helped the institution demonstrate strengthened security controls and risk reduction to their leadership and third parties, supporting a secure return to normal service. By progressing from emergency MDR during the incident to ongoing MDR, with Clarity Extend, the institution was able to carry that assurance forward, maintaining continuous monitoring and response as part of a strengthened security baseline.

“When credentials are sold, the hardest part isn’t reacting, it’s proving what’s true,” said the Incident Response Team Lead at Quorum Cyber. “Our job was to replace uncertainty with evidence, fast.  We confirmed the access path, reconstructed the attacker’s actions, and gave the customer the confidence to recover securely.”

Explore our managed services

Browse and compare our full range of Managed Security Services and contact us if you’d like to talk to an expert.


Safeguarding the Future of Education: Enhancing University Cyber Security with a Trusted Partner

A progressive UK-based university supports more than 10,000 students and 1,500 staff across multiple campuses. With a strong commitment to community engagement, the institution aims to widen access to higher education, address evolving skills demands, and deliver meaningful social and economic impact. It is also recognised for its strong graduate employment outcomes, helping to develop and retain skilled individuals across various sectors.

Cyber security has long been a strategic priority, as it is for most of the higher education sector. The university’s senior leadership recognised the need to bolster its ability to respond rapidly and effectively to potential cyber-attacks at any time, day or night.

“Our users are front and centre of our cyber security strategy,” says the University’s Director of Technology Services. “We see threats coming from multiple angles continuously, mostly in the form of phishing and spear phishing attacks attempting to deliver malware payloads.”

Extending the team with a trusted partner

To address growing cyber risks, the university sought a partner that could function as an extension of its internal team, offering automated, managed detection and response while allowing internal staff to focus on strategic initiatives. Out-of-hours security coverage was also a key requirement.

After a competitive tender process, the university selected Clarity Extend, a managed detection and response (MDR) service from Quorum Cyber. The service includes global threat detection, automated threat hunting, and sector-specific threat intelligence. The institution was particularly drawn to Quorum Cyber’s Microsoft-first approach and its robust incident response capabilities.

The Director of Technology Services adds: “We now have 24/7 managed detection and response operated by Quorum Cyber’s Security Operations Centre. We’ve gained reassurance from having mature and trusted processes, backed by a partner fully dedicated to managing and mitigating cyber threats.”

Achieving greater cyber resilience

The university continues to run a rigorous cyber incident response (IR) plan, including an annual tabletop exercise to ensure the entire organisation knows how to respond during a cyber event. This preparation is a vital part of maintaining business continuity.

Through its licensing agreement, the institution uses automated responses to specific types of suspicious system activity, significantly increasing operational efficiency. This is especially important for protecting students - seen as ‘frontline users’ - due to their constant interaction with digital platforms and sensitive information.

The customer platform, Clarity, plays a key role in incident transparency. It automatically generates detailed reports on threat activity, helping the technology team quickly understand and communicate incidents across the organisation.

A seamless extension of the team

“We trust Quorum Cyber as a true extension of our team,” their Director of Technology Services explains. “Their technical experts swiftly contain and mitigate threats and help restore services, which is critical to keeping operations running even during an incident.”

Nearly three years into the partnership, the university remains pleased with the deployment and ongoing service. The implementation phase, project management and monthly reviews have met expectations, and importantly, the value delivered continues to be consistent with what was promised during the procurement process.

Cyber reassurance, delivered

“We’ve always had a reliable service from Quorum Cyber - responsive and aligned to our needs,” the Director of Technology Services reflects. “I sleep better knowing we have a partner with the right expertise watching over our digital environment. They act immediately if there’s an issue, based on the controls we’ve agreed.

“In short, Quorum Cyber provides strategic cyber reassurance.”


Queen Mary University of London Fortifies Cyber Security with Long-term Partnership

As a member of the prestigious Russell Group of universities, Queen Mary University of London is a world-leading, research-intensive university with 32,000 students representing more than 170 nationalities. It offers over 240 degree programmes in a wide range of subjects from humanities and social sciences to medicine and dentistry through to science and engineering. The university conducts ground-breaking research programmes for the UK’s National Health Service (NHS) and numerous world-renowned specialist hospitals.

Cyber security incidents can happen at any time

When Queen Mary University identified a potential cyber security threat, it acted swiftly and decisively — demonstrating a strong commitment to protecting its digital infrastructure. The university reached out to Quorum Cyber, whose Incident Response (IR) and Threat Intelligence (TI) teams operate 24/7 to support organisations across all sectors. By the next day, their Emergency Managed Detection and Response (Emergency MDR) service was fully deployed, providing Queen Mary with around-the-clock monitoring and protection.

Quorum Cyber provided technical support and guidance on communicating to internal and external stakeholders. This comprehensive approach helped the university in its management of stakeholder relationship and reputation.

Forming a long-term partnership

Queen Mary University solidified its commitment to cyber security by entering into an agreement for Clarity Extend, our Managed Detection and Response (MDR) service, following a successful tender process.

This partnership ensures continuous monitoring, detection, and response across the university’s entire IT estate. The MDR service is delivered by Quorum Cyber’s Security Operations Centre (SOC) team, which is based in the UK.

The world-class research university demonstrated robust cyber resilience in the face of potential adversity. This case underscores the importance of both cyber security and resilience in maintaining the university’s global standing and operational integrity.

"Quorum Cyber expertly helped us navigate cyber security threats and supported us with stakeholder communications and insurance negotiations," said Richard Holland, Assistant Director of the Office CIO at Queen Mary University. "We were so impressed that partnering with them long-term was an easy decision."


US University Negotiates Multiple Cyber Security Challenges

Facing a daunting challenge

A leading university in the US faced multiple cyber security challenges that threatened its operations and data integrity. Limited evidence was available due to encryption, complicating efforts to trace and resolve security incidents. The university also had to manage the expectations of various stakeholders while dealing with an aggressive threat actor responsible for two distributed denial-of-service (DDoS) attacks. Additionally, the absence of firewall logs and file server records for data exfiltration posed significant challenges.

Bringing in a cyber security specialist

Needing to act swiftly, the university adopted a pragmatic approach, working with all available resources. The institution brought in Quorum Cyber to manage its cyber security. Quorum Cyber was engaged to enhance system management, and areas such as Microsoft Office365 review and triage were prioritised for rapid action. To manage expectations, daily updates and written reports were provided to stakeholders. Negotiations were leveraged to gather evidence of data exfiltration, ensuring transparency and accountability. Notably, the university decided not to make any ransom payment.

Safeguarding the university

Despite the complexities, the university achieved several key outcomes:

  • Comprehensive Analysis: Examination of logs confirmed several security incidents, including compromised accounts, lateral movement, and the presence of a ransomware payload
  • Partial Restoration: Some devices were restored before complete data collection, showcasing progress in system recovery
  • Data Handling: The university received samples of files and downloaded leaked data, providing insights into the breach's impact
  • Stakeholder Satisfaction: The university’s board approved the decision not to pay a ransom to the cybercriminals.

The university's proactive measures and commitment to transparency allowed it to navigate the cyber security incident while minimising financial loss. Although some data was compromised, the university's ability to restore operations and provide detailed analyses underscored its resilience and dedication to safeguarding its students, researchers, staff, and its reputation.

Contact us if you would like to discuss any aspects of your organisation's cyber security.


US University Navigates Data Recovery Challenges

Data encryption at exam finals time

A leading university faced a critical situation when its ESXi servers and virtual machines were encrypted by a cyber-attack. This incident coincided with a particularly challenging period, as it occurred during exam finals and the holiday season. Many students were using loaned devices and were off-campus, complicating communication and coordination efforts. The university decided against purchasing a ransomware decryptor, necessitating an alternative recovery strategy. Additional challenges included the university staff's unfamiliarity with their IT environment and a lack of trust between domain controllers, further complicating recovery efforts.

Planning and implementing recovery strategy

To address these challenges, the university implemented a comprehensive recovery strategy which involved the support of Quorum Cyber. The university’s strategy comprised:

  • Infrastructure Rebuild: The university rebuilt its ESX hosts using backups stored on Amazon Web Service (AWS), ensuring that critical infrastructure components were restored
  • Expert Recovery Teams: Quorum Cyber’s team restored the university's environment to enhance recovery efforts and ensure a thorough and efficient process
  • Security Software Deployment: Enhanced endpoint security and monitoring capabilities were deployed across the university's network.

An outstanding recovery

Through these targeted efforts, the university was able to achieve significant recovery milestones:

  • Infrastructure Restoration: The rebuilding of ESX hosts from AWS backups allowed the university to regain control over its IT infrastructure, restoring essential services and systems.
  • Collaborative Recovery Effort: The involvement of expert recovery teams facilitated a coordinated and effective response, demonstrating the importance of collaboration in crisis situations.
  • Enhanced Security Posture: Improved the university's security posture, providing greater protection against future threats.

The university's swift and strategic response to the cyber-attack enabled the institution to overcome significant challenges during a critical time. By leveraging expert resources and prioritising infrastructure restoration, the university successfully navigated the recovery process, underscoring its commitment to resilience and the protection of its academic community.

Contact us if you would like to strengthen your organisation's cyber security or cyber resilience.


Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content