// 2 CRITICAL · 3 CVE · 4 EXPLOIT IN THE LAST 24H
The ShinyHunters cybercriminal group has breached the University of Nottingham’s Oracle PeopleSoft system, exfiltrating 40GB of data including passport numbers, financial details, and sensitive personal information of nearly half a million individuals.

The ShinyHunters cybercriminal group breached the University of Nottingham’s student registration system on Tuesday, June 9, 2026, exposing the personal data of approximately 454,600 current and former students. Given that the university currently enrolls roughly 46,000 students, the breach affects nearly ten times the current student population, indicating a massive exposure of alumni records. The compromise targeted the university's Oracle PeopleSoft Campus Solutions instance, which is managed by a third-party provider. The stolen dataset includes financial records, UK National Insurance numbers, and—according to analysis by Have I Been Pwned—passport numbers, ethnicities, and disability status. Oracle did not respond to requests for comment from BleepingComputer at the time of publication.

Key Takeaways
  • ShinyHunters claimed credit for the attack on June 9, leaking an archive of over 40GB of stolen documents; Have I Been Pwned confirms between 454,600 and 455,000 individuals are affected.
  • The university identified unauthorized activity on its Campus Solutions system on Tuesday, June 9, and immediately took the systems offline to contain the incident.
  • Exposed data includes financial information, billing and payment details, full names, addresses, phone numbers, dates of birth, ethnicities, disabilities, and passport numbers.
  • The attack is part of a broader campaign targeting over 100 organizations running Oracle PeopleSoft instances.
"The University of Nottingham has been the victim of a cyber incident and a significant amount of data in our student record system has been accessed by a well-known cybercriminal group" — University of Nottingham spokesperson, via email to BleepingComputer

The Claim and the University's Response

ShinyHunters posted the claim on its leak site on June 9, 2026, attaching a document archive as proof of the compromise. In a direct statement to BleepingComputer, the group confirmed that the volume of exfiltrated data exceeds 40GB.

The University of Nottingham responded via an internal communication led by Jason Carter, Chief Governance and Risk Officer. Carter confirmed the detection of "unauthorised activity on its Campus Solutions system on Tuesday" and the immediate shutdown of the affected systems. Operating on a "precautionary assumption," Carter informed students that the university assumes four categories of information were accessed.

The university has reported the incident to Action Fraud and the Information Commissioner’s Office (ICO), the UK’s data protection regulator. The institution stated it is "working with the third party that maintains the platform to lead a forensic investigation."

Data Profile: From Billing to Passports

Analysis by Have I Been Pwned (HIBP) has quantified and qualified the exposed dataset. The service reports "455k unique email addresses" and a list of fields including "names, addresses, phone numbers, ethnicities, disabilities, passport numbers and information relating to academic enrolments and fee payments."

This level of granularity differs from the university's institutional disclosure. While the university confirmed aggregate categories—contact information, university details, personal data including NI numbers and "protected characteristics," and financial data—HIBP isolated specific fields such as ethnicities and disabilities. It remains unconfirmed whether full credit card numbers were exfiltrated or if the "credit card and payment details" mentioned by BleepingComputer refer to transaction records without full card digits.

Attack Mechanism: A "Gadget Chain" Against PeopleSoft

ShinyHunters told BleepingComputer they utilized a "gadget chain" that combines zero-day exploits with legacy vulnerabilities. The group emphasized that exploitation success "depends on the configuration of each instance." While the breach resulted in unauthorized access, the available brief does not confirm remote code execution (RCE) as the specific outcome.

The attack is part of a campaign that, according to BleepingComputer, has hit more than 100 organizations utilizing Oracle PeopleSoft. It has not been disclosed whether Nottingham’s instance was hosted on-premise or in the cloud, nor has the name of the third-party maintainer been released.

ERP Supply Chain as a Structural Liability

The University of Nottingham delegated the management of its PeopleSoft system to a "third party that maintains the platform." This outsourcing architecture, common in the education sector, does not mitigate the data controller's liability before the ICO. The university remains legally accountable for the protection of student data.

The case highlights a systemic tension: global universities accumulate decades of student records within centralized ERP platforms. When a compromise affects ten times the current student population, the duration of data retention becomes a significant impact multiplier.

Why It Matters

The Nottingham breach brings three critical elements to the forefront for the education and enterprise sectors. First is the scale: approximately 454,600 individuals—nearly ten times the current enrollment—demonstrates that university ERP systems maintain extensive historical cohorts, and their compromise has a magnified effect.

Second, the reporting structure of this incident relies on two primary independent editorial sources: BleepingComputer, which obtained direct statements from both the university and the criminal group, and the BBC, which reported on Jason Carter’s internal communication. Have I Been Pwned provides quantitative confirmation as a specialized source. Beyond this structure, the information has not been verified across additional independent sources.

Third, Oracle’s lack of response to BleepingComputer’s inquiry leaves an information vacuum. Other institutions running PeopleSoft instances are currently unable to supplement their risk assessments with official technical advisories or verified data.

The "precautionary assumption" adopted by the university expands the scope of notification beyond only the data verifiably exfiltrated. While this approach is prudent for protecting data subjects, it increases the communication burden and potential reputational damage, though it reduces the risk of regulatory underestimation. The available evidence suggests this was a cautionary choice in student communication rather than a documented legal defense strategy.

Information has been verified against the cited sources and is current as of the time of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. bbc.com
  3. haveibeenpwned.com
  4. aol.com
  5. deals.bleepingcomputer.com