The University of Nottingham confirmed on June 10, 2026 that a well-known cybercriminal group accessed a significant amount of data in its student record system. The university said current students and alumni were impacted, contacted affected people directly, and is working with Action Fraud, the ICO, and the third-party platform maintainer on forensics (support line: 0115 74 86500).
HIBP confirms 454,600 records
On June 11, Have I Been Pwned loaded 454,600 former and current student records after analyzing data tied to the ShinyHunters leak—names, addresses, phones, ethnicities, disabilities, passport numbers, and academic enrolment/fee-payment fields. BleepingComputer corroborated the count.
PeopleSoft campaign context
The incident sits inside a wider June 2026 ShinyHunters wave targeting Oracle PeopleSoft at 100+ organizations, mostly in education. Actor marketing cited ~40 GB of billing and campus-portal exports for UK, Malaysia, and China campuses—treat TB claims separately from the HIBP-indexed set until ICO filings match.
Action items
- Monitor official university email—not SMS links citing real student IDs or fee balances.
- Check HIBP and enable breach alerts on personal recovery email.
- Report suspicious finance or transcript requests to Action Fraud if you received a direct notice.
Canonical record: University of Nottingham 2026 on BreachHistory.
Sources: University of Nottingham, HIBP, BleepingComputer