The University of Oxford disclosed in June 2026 that vendor Group GTI reported a May 28 breach of its CareerConnect careers platform used by Oxford and other U.K. universities.
Confirmed exposure
- First and last names plus email addresses
- Encrypted CareerConnect passwords for users who did not sign in via SSO (passwords invalidated)
- No evidence that Oxford’s own systems, course files, appointments, or financial data were involved
Action items
- Reset CareerConnect passwords on next login and avoid reusing old credentials elsewhere.
- Enable MFA on Oxford SSO and personal email recovery accounts.
- Treat unexpected career or alumni phishing as suspicious—attackers may weaponize exposed names and emails.
Canonical record: Oxford CareerConnect 2026 on BreachHistory.
Sources: Oxford Careers Service, BleepingComputer