How a Database Dump Exposed 37,418 Damanhour University Users
HEROIC Cybersecurity analysts identified 37,418 user records from Damanhour University, an educational institution in Egypt, exposed in a database breach that surfaced on February 3, 2025. The leak, tied to the damanhour.edu.eg domain, contained email addresses, first and last names, gender, and birthdays pulled directly from the university's backend registration database.
Why This University Breach Is Dangerous
Academic records are tied to a specific, verifiable identity. When a university's user database leaks, attackers receive a ready-made list of real people, their full names, their birthdays, and an email address they almost certainly still use. That combination is the core starting point for identity theft, scholarship fraud, and targeted phishing aimed at alumni and current students.
What Was Exposed in Damanhour University
- 37,418 user records from damanhour.edu.eg
- Email addresses, including academic .edu.eg addresses
- First names and last names
- Gender
- Birthdays
- No passwords recovered in this dataset
Why This Matters
Email and date of birth are two of the most reliable knowledge-based identity fields on the internet. An attacker armed with both can reset passwords on accounts that use birthday verification, apply for credit or loans in another country, or run targeted phishing that impersonates university admissions or financial aid offices. Students who reuse their academic email password on cloud storage, learning tools, or social media also face direct account takeover risk.
How Database Breaches Hit Universities
University websites often combine a public CMS, a student portal, and several third-party plugins for admissions and registration. A single unpatched vulnerability, a forgotten test endpoint, or weak staff credentials can let an attacker query the main user table and export it wholesale. Once the raw database is out, it moves quickly from private forums to Telegram channels and onto aggregator sites where buyers cross-reference it with other leaked datasets.
Check If You Are Affected
HEROIC's DarkHive scanner indexes more than 400 billion exposed records, including the Damanhour University dataset. Search your academic or personal email to see if you were caught in the leak, rotate any reused passwords tied to that address, and turn on multi-factor authentication on email, banking, and cloud accounts.
Breach Breakdown
37,418 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds