University of Nottingham Data Breach Impacts More Than 450,000 Students
The University of Nottingham confirmed a major data breach affecting more than 450,000 current and former students after attackers accessed its student records system, exposing personal, academic, financial, and identity-related information that could increase the risk of phishing, fraud, and targeted scams.
The University of Nottingham has confirmed a major data breach affecting current and former students after a cybercriminal group gained access to its student records system.
The university, a major public research institution in the United Kingdom with more than 46,000 students and roughly 7,000 staff, said the incident exposed a significant amount of data stored in its student record platform. The breach has been reported to both Action Fraud and the U.K.’s Information Commissioner’s Office.
“The University of Nottingham has been the victim of a cyber incident and a significant amount of data in our student record system has been accessed by a well-known cybercriminal group,” the university said in a statement.
The university added that it is working with the third-party provider responsible for maintaining the affected platform as part of an ongoing forensic investigation.
While Nottingham has not publicly attributed the attack, the ShinyHunters extortion group claimed responsibility and posted samples of allegedly stolen files on its dark web leak site.
According to the group, the stolen dataset includes more than 40GB of documents tied to the University of Nottingham, as well as its Malaysia and China campuses. The attackers claim the data includes student finance records, billing and payment information, credit card-related details, and campus portal exports.
The group also claims the stolen records contain students’ full names, home addresses, IP addresses, phone numbers, and dates of birth.
Breach notification service Have I Been Pwned later analyzed the exposed data and said the incident affects approximately 454,600 current and former students. The exposed information reportedly includes email addresses, names, addresses, phone numbers, ethnicities, disability information, passport numbers, academic enrollment details, and fee payment information.
The scale and sensitivity of the exposed data make this a serious privacy incident. Student record systems often contain a combination of personal, academic, financial, and identity-related information. That type of data can be valuable to cybercriminals because it can be used for phishing, identity theft, financial fraud, account takeover attempts, and targeted social engineering.
The Nottingham breach is reportedly part of a broader campaign linked to ShinyHunters targeting Oracle PeopleSoft environments. PeopleSoft is an enterprise software platform widely used by universities, government agencies, and large organizations for human resources, finance, payroll, procurement, and campus administration.
According to reports, ShinyHunters has claimed to have stolen data from more than 100 organizations worldwide by compromising cloud and on-premises PeopleSoft instances. The group has alleged that its attacks rely on a combination of zero-day vulnerabilities and older flaws, though successful exploitation may depend on how each PeopleSoft environment is configured.
Oracle has reportedly been contacted for comment regarding whether it is aware of an actively exploited PeopleSoft zero-day vulnerability.
The University of Nottingham is the second major U.K. university to disclose a data breach in recent days. The University of Oxford recently confirmed that its CareerConnect careers services platform was compromised on May 28. Oxford also reported a separate breach earlier in May connected to ShinyHunters’ compromise of Instructure’s Canvas learning management system.
The wave of incidents highlights the growing threat facing higher education institutions, which often operate large, complex technology environments with numerous third-party systems, legacy applications, cloud platforms, and sensitive student records.
For affected students and alumni, the primary risks include phishing, credential theft, identity fraud, and targeted scams using legitimate personal or academic information. Individuals impacted by the breach should be cautious of emails, phone calls, or messages claiming to come from the university, financial offices, student services, or payment providers.
Recommended steps include changing passwords, enabling multi-factor authentication, monitoring financial accounts, watching for suspicious login alerts, and being cautious with unsolicited messages that reference university records, tuition payments, student finance, or account verification.
For universities and other organizations using PeopleSoft, the incident reinforces the need to review exposure, apply available security updates, restrict administrative access, monitor unusual data exports, audit third-party integrations, and investigate whether student or employee records may have been accessed.
The breach remains under investigation, and additional details may emerge as forensic teams analyze how the attackers accessed the student record system and what data was taken.
Comments
0 public comments
No comments yet
Be the first to add a comment to this article.
Add a comment
Please sign in to comment on this article.
Sign In