Nottingham University data breach affects over 450,000 students
The University of Nottingham says a cyber incident exposed student-record data, affecting 454,600 current and former students.
Intelligence analysis by GPT-5.4 Mini

The University of Nottingham says a well-known cybercriminal group accessed its student record system and exposed a significant amount of data. Have I Been Pwned says the breach affects 454,600 former and current students, while ShinyHunters claims it stole more than 40GB of documents.
A big university's student data was broken into, like someone sneaking into a giant filing cabinet. The stolen papers may include names, phone numbers, and school payment details for hundreds of thousands of people.
Analysis
The University of Nottingham confirmed that a hacking group accessed its student record system and exposed a significant amount of data. The university says it reported the incident to the UK Information Commissioner's Office and Action Fraud, and that a third party running the platform is helping with the forensic investigation.
According to the article, the ShinyHunters extortion gang claimed responsibility and posted what it says is stolen material as proof. The group claims it took more than 40GB of documents, including student finance records, billing and payment data, credit card and payment details, and portal exports from the university and its Malaysia and China campuses.
BleepingComputer says Have I Been Pwned analyzed the leaked data and concluded the breach affects 454,600 former and current students. The exposed information reportedly includes email addresses, names, addresses, phone numbers, ethnicities, disabilities, passport numbers, academic enrollment details, and fee-payment information.
The report also says this is part of a broader ShinyHunters campaign against cloud and on-premises Oracle PeopleSoft instances across more than 100 organizations worldwide. ShinyHunters told BleepingComputer it is using a mix of zero-days and older vulnerabilities, and that success depends on the target system's configuration. Oracle had not responded to the publication's request for comment at the time of writing.
Key points
- The University of Nottingham says a cyber incident exposed data in its student record system.
- Have I Been Pwned says the breach affects 454,600 former and current students.
- ShinyHunters claims it stole more than 40GB of documents from the university and its overseas campuses.
- The leaked data reportedly includes contact details, passport numbers, and academic and payment information.
- The article says the attack is part of a broader campaign against Oracle PeopleSoft instances.
The university has already reported the incident and says a forensic investigation is underway, which gives it a path to confirm what was accessed and harden the platform. If the investigation is thorough, it could also help other schools using similar systems spot weak points before they are attacked.
The exposed records reportedly include highly sensitive personal and financial details, so affected students may face scams or identity theft. If this is part of a wider PeopleSoft campaign, more universities and organizations could be at risk before the underlying exploit path is fully understood and patched.



