discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Nottingham University data breach affects over 450,000 students

The University of Nottingham says a cyber incident exposed student-record data, affecting 454,600 current and former students.

By Sergiu Gatlan·Jun 11·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Nottingham University data breach affects over 450,000 students
Image: bleepingcomputer.com

The University of Nottingham says a well-known cybercriminal group accessed its student record system and exposed a significant amount of data. Have I Been Pwned says the breach affects 454,600 former and current students, while ShinyHunters claims it stole more than 40GB of documents.

Why it matters

This is a large breach at a major university, with sensitive personal and academic data reportedly exposed. It also appears tied to a broader campaign against Oracle PeopleSoft systems, which raises the risk of more institutions being hit.

A big university's student data was broken into, like someone sneaking into a giant filing cabinet. The stolen papers may include names, phone numbers, and school payment details for hundreds of thousands of people.

Analysis

The University of Nottingham confirmed that a hacking group accessed its student record system and exposed a significant amount of data. The university says it reported the incident to the UK Information Commissioner's Office and Action Fraud, and that a third party running the platform is helping with the forensic investigation.

According to the article, the ShinyHunters extortion gang claimed responsibility and posted what it says is stolen material as proof. The group claims it took more than 40GB of documents, including student finance records, billing and payment data, credit card and payment details, and portal exports from the university and its Malaysia and China campuses.

BleepingComputer says Have I Been Pwned analyzed the leaked data and concluded the breach affects 454,600 former and current students. The exposed information reportedly includes email addresses, names, addresses, phone numbers, ethnicities, disabilities, passport numbers, academic enrollment details, and fee-payment information.

The report also says this is part of a broader ShinyHunters campaign against cloud and on-premises Oracle PeopleSoft instances across more than 100 organizations worldwide. ShinyHunters told BleepingComputer it is using a mix of zero-days and older vulnerabilities, and that success depends on the target system's configuration. Oracle had not responded to the publication's request for comment at the time of writing.

Key points

  • The University of Nottingham says a cyber incident exposed data in its student record system.
  • Have I Been Pwned says the breach affects 454,600 former and current students.
  • ShinyHunters claims it stole more than 40GB of documents from the university and its overseas campuses.
  • The leaked data reportedly includes contact details, passport numbers, and academic and payment information.
  • The article says the attack is part of a broader campaign against Oracle PeopleSoft instances.
The Upside

The university has already reported the incident and says a forensic investigation is underway, which gives it a path to confirm what was accessed and harden the platform. If the investigation is thorough, it could also help other schools using similar systems spot weak points before they are attacked.

The Downside

The exposed records reportedly include highly sensitive personal and financial details, so affected students may face scams or identity theft. If this is part of a wider PeopleSoft campaign, more universities and organizations could be at risk before the underlying exploit path is fully understood and patched.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityglobal-newsregulationsocietytech

Author

Sergiu Gatlan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 11, 2026

Source

bleepingcomputer.com

Share

Topics

securityglobal-newsregulationsocietytech

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…