The images in this article were generated with artificial intelligence. How we publish
The University of Nottingham confirmed this week an unauthorized access to its student management system, which, according to independent analysis, affects hundreds of thousands of records between current and former students. Incidents in university administrative systems are not isolated: here we talk about sensitive personal and financial information that facilitates fraud and identity supplantations.
Sources that have reviewed the filtered files point to a massive exfiltration - around 40 GB as claimed by the self-called ShinyHunters - that would include data such as names, addresses, birth dates, phone numbers, payment details and passport numbers. The Have I Been Pwned service has published a preliminary report that figures the impact on 454,600 people and details the variety of fields involved; it is appropriate to consult to identify if your mail is among those affected https: / / habebeenpwned.com / Breach / UniversityOfNottingham.

This attack is part of a broader campaign that is exploiting instances of Oracle PeopleSoft, an ERP suite very used in universities to manage from plates to finance and payroll. PeopleSoft is attractive to attackers because it concentrates critical data and, in many environments, it lives with custom configurations and pending patches, which multiplies the attack surfaces.
The alleged responsible group has claimed to have used operating chains that combine old vulnerabilities and undisclosed failures; according to public information, the effectiveness of these vectors depends to a large extent on the specific configuration of each facility. This implies that organizations with cloud or hybrid deployments and without adequate segmentation can be particularly vulnerable.
For the people concerned, immediate and practical actions are clear: review access to bank accounts and cards, activate and strengthen multifactor authentication where possible, change passwords if shared with the committed mail and sign fraud alerts with your bank. It is also recommended to consult identity monitoring services and to assess the possibility of a blocking or warning of fraud in credit agencies. If you believe that your official documents (passport, etc.) are committed, contact the issuer to know the steps to invalidate or renew them.
Educational institutions and providers must assume that such campaigns will continue. Priority measures include applying known patches and mitigations in all PeopleSoft environments, reviewing default configurations, segmenting networks, hardening remote access and increasing registration and monitoring to detect side movements. It is also essential to conduct intrusion tests and attack simulations that validate the actual detection and response of security teams before an attacker does.

From a legal and regulatory point of view, universities are required to report significant gaps to authorities such as the Information Commissioner's Office in the United Kingdom and the relevant security forces; Nottingham has already informed regulators and the police. If your organization needs guidance on incident management and reporting, the guidelines of the regulator and the national cybersecurity centre are useful resources for designing proportional and consistent responses https: / / ico.org.uk /.
This episode also links with recent commitments from other universities, such as the incident that affected career services at Oxford University, and highlights a trend: the extortion and filtering actors are targeting common suppliers and platforms to maximize impact. You can read Oxford's note about attacks on educational platforms in his official statement https: / / www.ox.ac.uk / news / 2026-05-08-canvas-incident.
In short, we are faced with a new sample of why the protection of critical administrative infrastructures should be given priority equivalent to that of academic systems: the data exposed cause real harm to individuals and institutional reputation. For users: monitor accounts and activate protections; for IT managers: park, securely and test detection and response; for managers: report, communicate clearly and provide support to those concerned. Cybersecurity in higher education requires sustained investment and coordination between universities, suppliers and regulators to prevent such incidents from becoming a standard.
Related
More news on the same subject.

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...

Isolated-vm Vulnerability allows memory corruption and sandbox escape
Security researchers have revealed critical vulnerability in the open source isolated-vm library - a Node.js binding to run unreliable JavaScript in isolated V8 engine instances...

Microsoft links more than 30 domains to MacSync Stealer for macOS with active data exfiltration
Microsoft has linked more than thirty web domains to MacSync Stealer, a malicious program focused on macOS that steals information. Microsoft researchers describe a repeated cha...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...

Lazarus Group returns with a campaign aimed at defense and aerospace that combines kernel rootkit and social recruitment
The North Korean group known as Lazarus Group has again shown that it continues to improve intrusion techniques for the defence and aerospace industry. According to the research...