2026-08-23NOTABLEHWZ confirms the theft and names no provider; the only source connecting a provider to it is the extortion group's own leak-site listing
HWZ service-provider data breach (Switzerland, 2026-08)
incident · incident:hwz-service-provider-breach-2026-08 single-source
HWZ Hochschule fuer Wirtschaft Zuerich told students and alumni in August 2026 that names, addresses, phone numbers, student-administration records, bank details and sick-leave data were stolen through the infrastructure of an external IT service provider rather than from the school's own systems. The extortion group Payload listed a Zurich-area data-centre operator two days earlier, naming eight affected customer domains including the school's; no source outside that listing connects the two (Inside Paradeplatz, 2026-08-22).
Aliases: HWZ Datenleck 2026
Coverage
1
first 2026-08-23 → last 2026-09-01
Latest activity
2026-09-01
HWZ confirms the theft and names no provider; the only source connecting a provider to it is the extortion…
Peak priority
notable
1 notable
Targets
education
sectors: education, public-sector, technology · regions: switzerland, europe
Sources cited
5
5 hosts
Defender insights
What each entry about HWZ service-provider data breach (Switzerland, 2026-08) tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessTrusted Relationship
Initial Access TA0001
T1199Trusted Relationship×1
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.
Evidence: 2026-08-23/payload-zurich-it-provider-hwz-student-data · ATT&CK page ↗
Entries about HWZ service-provider data breach (Switzerland, 2026-08) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Payload×1
Where this entity is cited
Source distribution
- ictk.ch1 (20%)
- inside-it.ch1 (20%)
- insideparadeplatz.ch1 (20%)
- netzwoche.ch1 (20%)
- ransomware.live1 (20%)
All cited sources (5)
- ictk.chictk.chhttps://ictk.ch/inhalt/hwz-opfer-eines-schweren-cyberangriffs
- inside-it.chInside IThttps://www.inside-it.ch/hwz-daten-landen-im-darkweb-20260831
- insideparadeplatz.chInside Paradeplatzhttps://insideparadeplatz.ch/2026/08/22/cyber-attacke-konto-daten-von-hwz-studenten-geschnappt/
- netzwoche.chNetzwochehttps://www.netzwoche.ch/news/2026-08-26/hacker-greifen-hwz-daten-ueber-externen-dienstleister-ab
- ransomware.liveRansomware.live (Payload leak-site listing)https://www.ransomware.live/id/UXVhbGlmbGV4IERhdGFjZW50ZXIgfCBIV1otU3R1ZGllbmduZ2UgKGZoLWh3ei5jaCksIG15ZW5iLmNoLCBldGNAcGF5bG9hZA==