ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

University of Nottingham confirms data breach exposing records of 454,600 students

The University of Nottingham has disclosed a cyberattack on its student records system, with a notorious extortion gang claiming to have stolen more than 40 gigabytes of sensitive personal and financial data.

Linked InXFacebook
bookmark_borderSave to Library

The University of Nottingham confirmed Wednesday that a cybercriminal group breached its student records system, exposing personal data belonging to hundreds of thousands of current and former students. The breach has been reported to the United Kingdom’s Information Commissioner’s Office and to Action Fraud.


The university, a public research institution with more than 46,000 students and 7,000 staff that ranks among the top 20 universities in the United Kingdom and the top 100 worldwide, said in a statement that "a significant amount of data" in its student record system had been accessed. "We are working with the third party that maintains the platform to lead a forensic investigation," the university said.


Breach notification service Have I Been Pwned assessed the incident Wednesday as affecting 454,600 current and former students, with exposed data including email addresses, names, home addresses, phone numbers, ethnicities, disabilities, passport numbers, and information related to academic enrollments and fee payments.


The ShinyHunters extortion gang claimed responsibility for the attack Tuesday, posting an archive of allegedly stolen documents on its dark web leak site as proof. The group claims to have taken more than 40GB of documents containing student finance data, billing and payment records, credit card and payment details, and campus portal exports spanning the university’s campuses in the United Kingdom, Malaysia, and China. ShinyHunters also alleged the stolen files include affected students’ full names, home addresses, IP addresses, phone numbers, and dates of birth. The university has not yet publicly attributed the attack to a specific group.


The Nottingham breach is part of a broader campaign in which ShinyHunters has allegedly stolen data from more than 100 organizations worldwide by compromising Oracle PeopleSoft installations, both cloud-hosted and on-premises. PeopleSoft is an enterprise software suite widely used to manage human resources, finance, payroll, supply chain, procurement, and campus administration at large institutions. ShinyHunters has said it is exploiting a combination of zero-day vulnerabilities and older unpatched flaws, and that successful exploitation varies depending on how individual instances are configured. Oracle had not responded to requests for comment on whether the company is aware of an actively exploited PeopleSoft zero-day vulnerability.


Nottingham is the second British university to disclose a breach within the span of a week. The University of Oxford revealed last week that its CareerConnect career services platform had been compromised on May 28. Oxford had separately reported an earlier breach in May following a ShinyHunters intrusion into Instructure’s Canvas learning management system.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543