Student Records Breach Exposes Durable Identity Data

The real risk here is not just that a university system was breached. A student-records platform held passport numbers, national insurance numbers, disabilities, and fee data for people who may have left years ago, so the exposure can feed fraud, impersonation, and targeted social engineering long after the account system is fixed. The University of Nottingham confirmed a cyber incident in its student records system. ShinyHunters claimed more than 40GB of stolen material, and Have I Been Pwned said the affected set is about 454,600 current and former students, with names, addresses, phone numbers, ethnicities, disabilities, passport numbers, national insurance numbers, and academic and fee records. That makes the blast radius much wider than an email leak. For universities that outsource student, HR, or customer records, the sensitive fields inside those platforms are the part that turns a breach into a long-term identity problem.

Part of the PlainSec briefing for 2026-06-12

Sources