ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Oxford University discloses second data breach of 2025 after career services platform compromised

The University of Oxford disclosed a data breach last week after its third-party career services provider, Group GTI, informed the university that its CareerConnect platform had been compromised, exposing personal data belonging to students, alumni, research staff, and employer users.


Oxford, founded in 1096 and widely recognized as the oldest university in the English-speaking world, is a collegiate research institution comprising 43 autonomous colleges with more than 26,000 students and roughly 5,900 staff. CareerConnect is also used by other UK universities to operate institution-specific career hubs, including King’s College London and the University of Manchester.


The breach occurred on May 28, when attackers gained access to users’ first names, last names, email addresses, and encrypted passwords. The password exposure applied only to users who authenticate directly through CareerConnect rather than through Single Sign-On. GTI invalidated the affected passwords, and users will be prompted to set new credentials at their next login.


Oxford said GTI’s assessment indicated the attack appeared focused on harvesting credentials, which could be used to facilitate phishing attempts. The university warned staff, students, and external CareerConnect users to be alert for suspicious or scam emails. "There is no evidence that course information, uploaded files, appointment information, or financial information were involved in this incident," the university stated.


The institution said the compromise was limited to GTI’s external system and that there is no indication university systems were affected. GTI and Oxford also said they found no evidence that students’ passwords or financial information had been accessed.


A university spokesperson told the cybersecurity publication BleepingComputer that the incident did not appear to involve ransomware and that there was no information regarding attribution or any claims of responsibility.


The CareerConnect breach is the second data incident Oxford has disclosed in 2025. In early May, the ShinyHunters extortion group breached Instructure’s Canvas learning management system, which Oxford uses. The hackers claimed to have stolen 280 million records tied to students and staff across more than 8,800 colleges, school districts, and online education platforms globally. Instructure subsequently reached an agreement with the group, stating that the stolen data was returned and that the hackers provided logs confirming its destruction. Oxford confirmed it was among the affected institutions, saying the exposed data was limited to usernames, Canvas email addresses, user-to-user messages on the platform, course names, and course enrollment information, and that its own systems were not compromised.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543