2026 University of Nottingham — student record system breach; 454,600 students and alumni (HIBP)
Data compromised
Names, addresses, phones, emails, ethnicities, disabilities, passport numbers, academic enrolment and fee-payment data per HIBP analysis of leaked dataset
Technical writeup
On June 10, 2026 the University of Nottingham published an official notice stating it was the victim of a cyber incident in which a significant amount of data in its student record system was accessed by an external third party, naming a well-known cybercriminal group and working with the third-party platform maintainer on a forensic investigation. The university said current students and alumni were impacted, contacted affected individuals directly, and coordinated with Action Fraud and the UK ICO (support line 0115 74 86500). By June 11, 2026, Have I Been Pwned loaded 454,600 former and current student records with extensive personal and academic fields after analyzing data published following the ShinyHunters Oracle PeopleSoft extortion wave; BleepingComputer corroborated the HIBP count. ShinyHunters separately claimed roughly 40 GB of billing and campus-portal exports for UK, Malaysia, and China campuses—volumes beyond the HIBP email-indexed set and not fully attested in the university notice.
Root cause
Cyber incident; ShinyHunters Oracle PeopleSoft extortion campaign; external access to student record platform maintained by third party
References
- https://www.nottingham.ac.uk/currentstudents/news/student-and-alumni-data-has-been-compromised-in-a-data-security-incident
- https://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/
- https://haveibeenpwned.com/Breach/UniversityOfNottingham
- https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/
- https://www.securityweek.com/university-of-nottingham-confirms-breach-after-hackers-leak-data/