The images in this article were generated with artificial intelligence. How we publish
The University of Oxford confirmed last week that its CareerConnect professional service platform, managed by the external supplier Group GTI, suffered an intrusion on May 28 that allowed attackers to access names, surnames, e-mail addresses and passwords stored locally for users who do not use Single Sign-On (SSO). This is a gap mainly aimed at collecting credentials, an increasingly common goal because it opens the door to post-phishing, password reuse attacks and account kidnapping in other services.
The incident affects a number of institutions that use the same platform - including King's College London and the University of Manchester - which again highlights the systemic risk of the digital supply chain in higher education: a failure in a supplier can impact many universities even if their own networks have not been compromised. Oxford has indicated that for now there is no evidence of access to internal university systems, financial information or uploaded files, and that GTI has invalidated the affected local passwords; the official university statement explains these measures and the limits of the known scope Here..

This episode comes weeks after another incident that affected the academic community: the leak linked to the learning management system Canvas de Instructure, which included data from millions of users and in which Oxford was also affected in its user capacity, according to its own communication. The recurrence of incidents on third-party platforms stresses that institutions cannot fully delegate risk management; require continuous transparency, controls and safety tests from their suppliers. More official details on the Canvas incident can be found in the university note published in May.
From the technical point of view, although the passwords are described as "encrypted," public documentation rarely details the exact hashing and jumping scheme used; knowing whether brute force-resistant algorithms (e.g. bcrypt, Argon2) are used is critical to assess the real risk that passwords can be discovered after the leak. Without transparency as to how these credentials are stored, the danger of their deciphering or reusing by attackers persists and good practices indicate that suppliers should publish forensic audits or reports that demonstrate the robustness of storage and containment measures.

For users and affected personnel, the immediate recommendations are clear: change passwords in CareerConnect if you have access with a local credential, enable and prioritize the use of SSO and, when available, activate multi-factor authentication (MFA) in any academic or professional service. In addition, be attentive to suspicious emails that call for the restoration of passwords or include unexpected links; the stated objective of the incident was to collect credentials to facilitate phishing and control attacks and therefore surveillance of fraudulent communications must be high.
For IT officials in institutions that depend on external suppliers, the lesson is twofold: on the one hand, to strengthen contractual clauses requiring immediate notification of incidents, response tests and mediation measures; on the other, to carry out regular risk assessments that include independent security tests, data encryption requirements at rest and in transit, and the need for key rotation and secret management policies. Incident response exercises and attack simulations on third-party services help prepare teams to detect and contain leaks before they climb.
Finally, given the potential impact on personal data, institutions should consider the applicable regulatory obligations and the possible need to notify data protection authorities and the persons concerned; the United Kingdom has practical guidance for these situations on the website of the Office of the Information Commissioner (ICO) available at ico.org.uk. Prevention and transparency are the best public defence: demand security standards from suppliers, apply universal MFA and educate the community about the risk of phishing will reduce the opportunity window for attackers.
Related
More news on the same subject.

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...

Isolated-vm Vulnerability allows memory corruption and sandbox escape
Security researchers have revealed critical vulnerability in the open source isolated-vm library - a Node.js binding to run unreliable JavaScript in isolated V8 engine instances...

Microsoft links more than 30 domains to MacSync Stealer for macOS with active data exfiltration
Microsoft has linked more than thirty web domains to MacSync Stealer, a malicious program focused on macOS that steals information. Microsoft researchers describe a repeated cha...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...

Lazarus Group returns with a campaign aimed at defense and aerospace that combines kernel rootkit and social recruitment
The North Korean group known as Lazarus Group has again shown that it continues to improve intrusion techniques for the defence and aerospace industry. According to the research...