UASLP data leak exposes student photos
Local reports say allegedly hacked UASLP data was posted publicly, including personal information and photos of students.
Local reports attribute the public release of allegedly hacked data from the Autonomous University of San Luis Potosí to an actor identifying as zfo$. According to those reports, the leak includes personal information and student photos, while the university acknowledged a recent intrusion into its systems.
Local reports attribute the publication of allegedly hacked data from the Autonomous University of San Luis Potosí, or UASLP, to an actor identifying as zfo$. According to those accounts, the leak includes students' personal information and facial photos, with figures that hover around 940 records. The university, according to the same sources, acknowledged a recent intrusion into its systems, but could not say whether the material released publicly came from that incident.
What information may have been exposed?
The material described in the reports combines personal data with images of students. PulsosLP said the allegedly leaked file would cover 940 students from the northern zone and 878 photographs, while a Kalir/Pulse brief describes a database of about 940 students with photos of their faces.
That mix of personal data and images raises the risk of identity theft, harassment, and social engineering attacks, according to the Kalir/Pulse brief. Local coverage also notes that neither the number of records nor the attribution has been independently confirmed in the sources reviewed.
What was said about the incident and the phishing that followed?
UASLP acknowledged, according to PulsosLP, that its computer systems were recently breached, but it could not determine whether the public leak stems from that event. At the same time, Potosí Noticias reported that several faculties issued internal warnings about phishing emails and fake virtual meetings aimed at institutional accounts.
Those alerts were circulated weeks after a cyberattack that affected various systems in early August and left information on some servers still encrypted, according to Potosí Noticias. The internal recommendations ask recipients to verify that the sender uses @uaslp.mx, distrust messages that pressure users over account blocks or service suspensions, check for spelling errors, and avoid handing over passwords, personal data, or confidential information.
They also advise reviewing links whose actual destination does not match the visible text in the email. Another local report, published on September 10, again said academic and personal information from nearly 1,000 students may have circulated online, in line with the figures already mentioned, although it did not independently confirm the exact source of the leak or the identity of the actor involved.
Sources
- Filtración de datos de 940 estudiantes de la UASLP con fotografíaspulse.kalir.io· Kalir Brief - Pulse
- Facultades de la UASLP advierten de phishingpotosinoticias.com· Potosí Noticias
- Difunden datos "hackeados" de la UASLPpulsoslp.com.mx· PulsosLP
- Detienen a hombre señalado por agredir a tres maestros en escuela de SLPpotosinoticias.com· Potosí Noticias



