Mass Filtration at Nottingham University exposes personal and financial data for hundreds of thousands of students and former students

Author: Published 4 min de lectura 272 reading

The images in this article were generated with artificial intelligence. How we publish

The University of Nottingham confirmed this week an unauthorized access to its student management system, which, according to independent analysis, affects hundreds of thousands of records between current and former students. Incidents in university administrative systems are not isolated: here we talk about sensitive personal and financial information that facilitates fraud and identity supplantations.

Sources that have reviewed the filtered files point to a massive exfiltration - around 40 GB as claimed by the self-called ShinyHunters - that would include data such as names, addresses, birth dates, phone numbers, payment details and passport numbers. The Have I Been Pwned service has published a preliminary report that figures the impact on 454,600 people and details the variety of fields involved; it is appropriate to consult to identify if your mail is among those affected https: / / habebeenpwned.com / Breach / UniversityOfNottingham.

Mass Filtration at Nottingham University exposes personal and financial data for hundreds of thousands of students and former students
Image generated with IA.

This attack is part of a broader campaign that is exploiting instances of Oracle PeopleSoft, an ERP suite very used in universities to manage from plates to finance and payroll. PeopleSoft is attractive to attackers because it concentrates critical data and, in many environments, it lives with custom configurations and pending patches, which multiplies the attack surfaces.

The alleged responsible group has claimed to have used operating chains that combine old vulnerabilities and undisclosed failures; according to public information, the effectiveness of these vectors depends to a large extent on the specific configuration of each facility. This implies that organizations with cloud or hybrid deployments and without adequate segmentation can be particularly vulnerable.

For the people concerned, immediate and practical actions are clear: review access to bank accounts and cards, activate and strengthen multifactor authentication where possible, change passwords if shared with the committed mail and sign fraud alerts with your bank. It is also recommended to consult identity monitoring services and to assess the possibility of a blocking or warning of fraud in credit agencies. If you believe that your official documents (passport, etc.) are committed, contact the issuer to know the steps to invalidate or renew them.

Educational institutions and providers must assume that such campaigns will continue. Priority measures include applying known patches and mitigations in all PeopleSoft environments, reviewing default configurations, segmenting networks, hardening remote access and increasing registration and monitoring to detect side movements. It is also essential to conduct intrusion tests and attack simulations that validate the actual detection and response of security teams before an attacker does.

Mass Filtration at Nottingham University exposes personal and financial data for hundreds of thousands of students and former students
Image generated with IA.

From a legal and regulatory point of view, universities are required to report significant gaps to authorities such as the Information Commissioner's Office in the United Kingdom and the relevant security forces; Nottingham has already informed regulators and the police. If your organization needs guidance on incident management and reporting, the guidelines of the regulator and the national cybersecurity centre are useful resources for designing proportional and consistent responses https: / / ico.org.uk /.

This episode also links with recent commitments from other universities, such as the incident that affected career services at Oxford University, and highlights a trend: the extortion and filtering actors are targeting common suppliers and platforms to maximize impact. You can read Oxford's note about attacks on educational platforms in his official statement https: / / www.ox.ac.uk / news / 2026-05-08-canvas-incident.

In short, we are faced with a new sample of why the protection of critical administrative infrastructures should be given priority equivalent to that of academic systems: the data exposed cause real harm to individuals and institutional reputation. For users: monitor accounts and activate protections; for IT managers: park, securely and test detection and response; for managers: report, communicate clearly and provide support to those concerned. Cybersecurity in higher education requires sustained investment and coordination between universities, suppliers and regulators to prevent such incidents from becoming a standard.

Coverage

Related

More news on the same subject.