← University of Nottingham

2026 University of Nottingham — Campus Solutions / WebLogic RCE; 454,600 students & alumni (HIBP); UK/China/Malaysia campuses

2026 454.6K records affected Share on X

Data compromised

Names, addresses, phones, emails, ethnicities, disabilities, passport numbers, academic enrolment and fee-payment data (HIBP). University precautionary list also includes financial/fee records, bursary and visa information for some students/alumni/applicants. Actor separately claimed ~40 GB spanning UK, Malaysia, and China campus exports — volumes beyond the HIBP email-indexed set.

Technical writeup

Verified — University of Nottingham official notices (student/alumni page and cyber-attack alert updated through at least 22 July 2026) plus HIBP load and trade press. On 9 June 2026 the university identified unauthorised activity in its Campus Solutions student records platform, took systems offline, and reported to the ICO, Action Fraud, Office for Students, NCSC and UCAS. July forensic update: attackers exploited an Oracle WebLogic vulnerability supporting Campus Solutions, allowing unauthorised remote code execution; the university said it did not receive a direct ransom demand. Impact spans the university’s UK, China and Malaysia campus community (students, some alumni and applicants). HIBP loaded 454,600 former and current student records by 11 June 2026 with extensive personal and academic fields after data published in the ShinyHunters Oracle PeopleSoft extortion wave. ShinyHunters separately claimed roughly 40 GB of billing and campus-portal exports for UK, Malaysia and China campuses — volumes beyond the HIBP email-indexed set and not fully attested as a single company count. Helpline 0115 74 86500; free credit monitoring offered to students.

Root cause

Oracle WebLogic vulnerability on Campus Solutions student records platform enabled remote code execution (university forensics, July 2026 update); ShinyHunters Oracle PeopleSoft / campus-portal extortion wave

References