Oxford University Discloses Data Breach After Third-Party Careers Platform Compromise

Oxford University Discloses Data Breach After Third-Party Careers Platform Compromise

Share Facebook X LinkedIn Email

Oxford University disclosed a data breach after its third-party CareerConnect careers platform was compromised, exposing names, email addresses, and encrypted passwords for some users while prompting password resets and phishing warnings.

The University of Oxford has disclosed a data breach after being notified that its third-party careers platform provider, Group GTI, had suffered a security incident affecting the CareerConnect platform.

CareerConnect is used by Oxford to provide career services to students, alumni, research staff, and employers. The platform is also used by other UK educational institutions, including King’s College London and the University of Manchester, to operate institution-specific careers portals.

Oxford said the breach occurred on May 28, when attackers gained unauthorized access to data stored within the CareerConnect platform. The exposed information included users’ first names, last names, email addresses, and encrypted passwords for accounts that do not use Single Sign-On.

According to the university, alumni, research staff, and employer users who access CareerConnect with locally stored passwords were affected. Group GTI has invalidated those passwords, and impacted users will be required to reset them the next time they sign in.

Oxford stated that there is currently no evidence that course information, uploaded files, appointment details, or financial information were accessed during the incident. The university also said there is no evidence that Oxford’s internal systems were compromised, emphasizing that the breach was limited to Group GTI’s third-party platform.

Group GTI has indicated that the attack appeared to be focused on credential collection. As a result, Oxford has warned students, staff, alumni, and external CareerConnect users to remain alert for phishing emails, scam messages, and other suspicious communications that may attempt to use information obtained from the breach.

The university said there is no evidence that student passwords or financial data were accessed. However, users who reused their CareerConnect password on other services should change those passwords immediately as a precaution.

This marks the second data breach disclosed by Oxford University this year. In May, the university confirmed it was affected by the breach of Instructure’s Canvas learning management system, which was claimed by the ShinyHunters extortion group. That incident exposed limited Canvas-related information, including usernames, email addresses, course names, enrolment information, and messages exchanged through the platform.

Oxford said at the time that its internal systems were not compromised in the Canvas incident. Similarly, in the CareerConnect breach, the university has stated that the impact appears limited to the third-party provider’s platform.

The latest incident highlights the continued cybersecurity risks associated with third-party education technology providers. Universities increasingly rely on external platforms for career services, learning management, admissions, collaboration, and student engagement, creating a broader attack surface outside of direct institutional control.

Affected CareerConnect users should reset their passwords when prompted, enable multi-factor authentication where available, avoid reusing passwords across services, and be cautious of emails requesting login details or directing them to unfamiliar sign-in pages.

Zach Miles
More from this author

Zach Miles

A polished young business and technology professional with a sharp eye for emerging trends, market movement, and innovation. He brings a confident, modern pr...

View author profile →
Discussion

Comments

0 public comments

No comments yet

Be the first to add a comment to this article.

Add a comment

Sign In