Breaches · 95 days ago
The real risk here is not just that a university system was breached. A student-records platform held passport numbers, national insurance numbers, disabilities, and fee data for people who may have left years ago, so the exposure can feed fraud, impersonation, and targeted social engineering long after the account system is fixed.
The University of Nottingham confirmed a cyber incident in its student records system. ShinyHunters claimed more than 40GB of stolen material, and Have I Been Pwned said the affected set is about 454,600 current and former students, with names, addresses, phone numbers, ethnicities, disabilities, passport numbers, national insurance numbers, and academic and fee records.
That makes the blast radius much wider than an email leak. For universities that outsource student, HR, or customer records, the sensitive fields inside those platforms are the part that turns a breach into a long-term identity problem.
3 sources covering this story
The Record from Recorded Future
University of Nottingham confirms cyber incident as Shiny Hunters group claims data theft
According to the university’s statement, it is still working to understand what data has been accessed and said it had already directly contacted affected students and alumni, potentially including those in its foreign campuses in Malaysia and China as well as in Nottingham.
University of Nottingham Confirms Breach After Hackers Leak Data
The ShinyHunters hacker group has taken credit for the attack, leaking more than 450,000 email addresses and other information.
Nottingham University data breach affects over 450,000 students
The University of Nottingham confirmed on Wednesday that a hacking group gained access to its student records system in a breach affecting both current students and alums.
Part of the PlainSec briefing for 2026-06-12