-
A hacker claims to have stolen 30 TB of data from more than 30 universities around the world.
-
The seller wants $10,000 for the full package and offers free samples to buyers.
-
No university has confirmed a breach yet, and the seller’s history and identity remain unclear.
A hacker is trying to sell a huge batch of data. The seller claims it holds records from over 30 universities. Together, the files reportedly add up to 30 TB.
According to a post shared by Dark Web Intelligence, the person behind the listing is asking $10,000 for everything.
The seller also says buyers can request sample files before paying. Nobody has proven the claim yet. Still, the size and scope make it worth watching closely.
What the Listing Says
The post names several well known schools. Stanford University appears on the list. So does the University of Pennsylvania and Yale University. Miami University is also named, along with Southern Illinois University School of Medicine.
Clark University shows up too. The list also includes Avantika University and G.H. Raisoni University. A screenshot attached to the post shows folders. These folders carry names that match different university and .edu web addresses.
If the claim turns out to be true, this could become a major story. University systems often hold a lot of private information. This can include student records and staff files. It can also include research data, login details, and other school documents. A breach across dozens of schools at once could cause damage far beyond each single campus. Students, teachers, and staff could all feel the effects.
However, nothing confirms the story just yet. The information available right now does not prove every named school got hacked. It also does not confirm that the stolen files truly reach 30 TB in size. Some of the data, if it is real, might not even come from a fresh hack. It could instead trace back to older leaks or third party tools tied to these schools.
Doubts About the Seller
Little is known about the person selling this data. According to Dark Web Intelligence, the seller seems new to the forum where the post appeared. The account shows barely any history or track record.
The screenshot gives no strong signs of trust or reputation either. This matters a lot. Sellers with little background are harder to trust. Buyers, researchers, and reporters should treat the claim carefully until real proof shows up.
Checking a claim like this takes real work. Analysts would need to look at sample files the seller offers. They would need to test whether the data is genuine and sensitive. They would also need to figure out when the files were taken. Comparing the data against past leaks helps too. This step can show if the files are new or just recycled from an older breach.
There is some past context that adds weight to the story. Earlier in 2026, a hacking effort tied to the group known as ShinyHunters targeted education technology tools. Public records tied to that event listed many schools.
Avantika University showed up in one such list, based on a report from The Daily Californian. That said, this earlier event should not be mixed up with the new 30 TB claim. Nothing links the two cases together right now. They appear to be separate stories that simply share one school’s name.
Why this Still Matters
Even though nothing is confirmed, the claim deserves attention. Big claims like this sometimes turn out to be exaggerated. Other times, they turn into real, serious breaches. If credible samples appear, or if even one named school confirms an attack, the story could grow fast. It could turn into one of the largest education data leaks in recent memory.
The University of Warsaw confirmed a March 2026 ransomware attack that exposed students’ and staff members’ personal data, including PESEL numbers. The attackers demanded €400,000 to prevent publication of the stolen information.
For now, schools, students, and staff should stay alert but calm. No official confirmation exists yet from any of the named universities. The $10,000 price tag and the 30 TB figure remain unverified numbers. They come from the seller, not from independent proof.
People connected to these schools can still take simple steps. Watch for unusual emails claiming to come from school offices. Avoid clicking links inside messages that feel off or unexpected. Keep passwords strong, and avoid using the same one across different accounts. Turning on two-factor login adds another useful layer of safety.
Reporters and researchers will likely keep digging into this case. Until solid proof appears, the 30 TB claim stays just that, a claim. The alleged theft affecting more than 30 universities has not been independently verified.
Anyone following this story should watch for updates from the named schools themselves. Official statements, if they come, will offer the clearest picture of what really happened.