Find notable cyber news and cases, enriched with sources, timelines, and signals.

University of Nottingham hit by cyberattack

Incident
First reported
Last updated
Happening score
H score 68
2 unique sources, 2 articles

Summary

Hide ▲

The University of Nottingham said a well-known cybercriminal group accessed its student record system, exposing a significant amount of data affecting current students and alumni, and reported the incident to Action Fraud and the Information Commissioner's Office. ShinyHunters later claimed responsibility and said it stole more than 40GB of documents from the university's UK, Malaysia and China campuses. Have I Been Pwned estimated the breach affects 454,600 former and current students. A separate Mandiant report tied the wider Oracle PeopleSoft campaign to CVE-2026-35273 and said universities were hit hardest.

Related Happenings

Oracle PeopleSoft broad zero-day exploitation campaign

Exploitation Wave
H score82 First: 29.06.2026 13:00 Last: 29.06.2026 13:00 Sources 1

About this happening: A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...

Klue Battlecards app Salesforce customer data leak

Data Leak
H score41 First: 19.06.2026 12:03 Last: 19.06.2026 12:03 Sources 1

About this happening: A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue...

Latest development: 20.06.2026 01:31

Icarus publicly claimed responsibility on its data leak site for the Klue-related Salesforce data theft and pressured Klue and affected organizations to contact the group through Session to avoid publication of stolen data. The same campaign was also tied to additional victims including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity, with most reporting theft from Salesforce instances rather than compromise of their core platforms or infrastructure.

Infinite Campus hit by data theft breach linked to ShinyHunters

Incident
H score51 First: 15.06.2026 15:38 Last: 15.06.2026 15:38 Sources 1

About this happening: Infinite Campus suffered a Salesforce data theft breach that exposed more than 137,000 school staff accounts, putting staff contact and account data at risk. The compr...

Oracle PeopleSoft PeopleTools zero-day RCE (CVE-2026-35273)

Vulnerability
H score58 First: 11.06.2026 22:39 Last: 11.06.2026 22:39 Sources 1

How related: The flaw, CVE-2026-35273, is a remote code execution bug in PeopleSoft Enterprise PeopleTools rated 9.8 out of 10.

About this happening: Oracle PeopleSoft PeopleTools CVE-2026-35273 is a critical zero-day RCE affecting PeopleSoft Enterprise PeopleTools 8.61 and 8.62. Oracle released emergency mitigati...

Latest development: 29.06.2026 23:40

Nissan says it suffered a data breach affecting current and former employees after attackers exploited an Oracle PeopleSoft zero-day associated with CVE-2026-35273. Oracle informed Nissan that personnel records of hundreds of companies may have been obtained and that Nissan was specifically targeted, with potentially exposed data including contact details, banking information, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary data for employees in the United States, Canada, Mexico, and Brazil.

Nottingham University data publication on ShinyHunters leak site

Data Leak
H score68 First: 10.06.2026 21:31 Last: 10.06.2026 21:31 Sources 1

How related: In a post on their dark web leak site, the cybercrime group claims to have stolen over 40GB of documents containing student finance data, billing and payment information, credit card and payment details, and campus portal exports from the University of Nottingham and its Malaysia and China campuses

About this happening: Nottingham University data was published on the ShinyHunters leak site after the group claimed access to the university’s student records system. The exposed material...

Timeline

  1. 11.06.2026 10:27 1 articles · 1mo ago

    ShinyHunters claims responsibility for the University of Nottingham breach

    Attribution Update

    ShinyHunters claimed responsibility for unauthorized access to the University of Nottingham's student records system and shared an archive of allegedly stolen documents as proof.

    Show sources
  2. 11.06.2026 10:27 1 articles · 1mo ago

    ShinyHunters says it stole over 40GB from University of Nottingham systems

    Victim Impact Update

    ShinyHunters said it stole over 40GB of documents from the University of Nottingham and its Malaysia and China campuses, including student finance data, billing and payment information, credit card and payment details, campus portal exports, and personal data such as names, home addresses, IP addresses, phone numbers, and dates of birth.

    Show sources
  3. 11.06.2026 10:27 3 articles · 1mo ago

    University of Nottingham confirms student records access and reports the breach

    Initial Disclosure

    The University of Nottingham said a well-known cybercriminal group accessed its student record system, exposed a significant amount of data affecting current students and alums, and reported the incident to Action Fraud and the Information Commissioner's Office; Have I Been Pwned later estimated the breach affects 454,600 former and current students.

    Show sources