Jul 31, 2026
Policy

APUC cyberattack exposed historic data at Scottish university procurement body

APUC says attackers accessed historic data, with no operational disruption, while it investigates claims that information was stolen.

Renata Fuchs

By Renata Fuchs · Policy Reporter

· 3 min read

APUC cyberattack exposed historic data at Scottish university procurement body
Photo: The Register

Advanced Procurement for Universities and Colleges confirmed an APUC cyberattack in which intruders accessed historic data on its IT systems earlier this month, according to comments given to The Register. The Scottish procurement body said it contained the incident quickly, brought in external technical specialists and has not seen disruption to its daily operations.

APUC told The Register it had found suspicious activity involving unauthorized access to some older data. The organization said it is still assessing the scope of the incident and investigating a claim by the group behind the access that it took some of that data.

The body said it has notified the relevant authorities and will continue working with them. It did not disclose what categories of data may have been accessed, how many institutions or suppliers could be affected, or whether any personal information was involved.

What happened in the APUC cyberattack?

APUC said attackers gained access to certain historic data in a mid-July intrusion and that the incident was contained after suspicious activity was identified. The organization said the same group has claimed to have removed some historic data, a claim APUC said it is investigating as a priority.

The Register reported that it approached APUC after receiving information from sources about the incident. Those sources claimed the organization had received an extortion demand from the criminals involved, but The Register said it had not independently confirmed that detail.

The Register also reported that it understood the attackers claimed to have taken APUC data going back 20 years and to have obtained administrator access through an employee account. APUC was asked about those claims, whether ransomware was used and whether any of the information was inaccurate. Its spokesperson did not address those questions, according to The Register.

Why APUC matters to Scottish higher education

APUC is Scotland’s procurement center of expertise for universities and colleges. It is one of eight members of UK Universities Purchasing Consortia, the group of purchasing organizations that negotiate agreements with approved suppliers for higher education institutions.

The practical role is significant: APUC sets up Framework Agreements, which allow Scottish universities and colleges to buy goods and services from pre-approved suppliers under agreed terms rather than running a fresh procurement process for each purchase. The organization lists hundreds of these agreements, covering contracts collectively valued at hundreds of millions of pounds.

That makes the attack relevant beyond APUC’s own systems. Procurement hubs can hold supplier, contract and institutional information that may be useful to criminals even when current operations are not interrupted. APUC has not said what specific files were accessed or whether any live procurement activity was affected.

At the time of The Register’s report, APUC did not appear on major ransomware or extortion groups’ data leak sites. Absence from those sites does not resolve whether data was taken, and APUC’s public position remains that it is investigating the claim while cooperating with authorities.

This story draws on original reporting from The Register.

More from Policy

All Policy →