University of Nottingham hit by cyberattack
Incident
Summary
Hide ▲
Show ▼
The University of Nottingham said a well-known cybercriminal group accessed its student record system, exposing a significant amount of data affecting current students and alumni, and reported the incident to Action Fraud and the Information Commissioner's Office. ShinyHunters later claimed responsibility and said it stole more than 40GB of documents from the university's UK, Malaysia and China campuses. Have I Been Pwned estimated the breach affects 454,600 former and current students. A separate Mandiant report tied the wider Oracle PeopleSoft campaign to CVE-2026-35273 and said universities were hit hardest.
Related Happenings
Oracle PeopleSoft broad zero-day exploitation campaign
Exploitation Wave
H score82
First: 29.06.2026 13:00
Last: 29.06.2026 13:00
Sources 1
About this happening:
A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...
Oracle PeopleSoft broad zero-day exploitation campaign
Exploitation WaveAbout this happening: A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...
Klue Battlecards app Salesforce customer data leak
Data Leak
H score41
First: 19.06.2026 12:03
Last: 19.06.2026 12:03
Sources 1
About this happening:
A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue...
Klue Battlecards app Salesforce customer data leak
Data LeakAbout this happening: A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue...
Latest development: 20.06.2026 01:31
Icarus publicly claimed responsibility on its data leak site for the Klue-related Salesforce data theft and pressured Klue and affected organizations to contact the group through Session to avoid publication of stolen data. The same campaign was also tied to additional victims including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity, with most reporting theft from Salesforce instances rather than compromise of their core platforms or infrastructure.
Infinite Campus hit by data theft breach linked to ShinyHunters
Incident
H score51
First: 15.06.2026 15:38
Last: 15.06.2026 15:38
Sources 1
About this happening:
Infinite Campus suffered a Salesforce data theft breach that exposed more than 137,000 school staff accounts, putting staff contact and account data at risk. The compr...
Infinite Campus hit by data theft breach linked to ShinyHunters
IncidentAbout this happening: Infinite Campus suffered a Salesforce data theft breach that exposed more than 137,000 school staff accounts, putting staff contact and account data at risk. The compr...
Oracle PeopleSoft PeopleTools zero-day RCE (CVE-2026-35273)
Vulnerability
H score58
First: 11.06.2026 22:39
Last: 11.06.2026 22:39
Sources 1
How related:
The flaw, CVE-2026-35273, is a remote code execution bug in PeopleSoft Enterprise PeopleTools rated 9.8 out of 10.
About this happening:
Oracle PeopleSoft PeopleTools CVE-2026-35273 is a critical zero-day RCE affecting PeopleSoft Enterprise PeopleTools 8.61 and 8.62. Oracle released emergency mitigati...
Oracle PeopleSoft PeopleTools zero-day RCE (CVE-2026-35273)
VulnerabilityHow related: The flaw, CVE-2026-35273, is a remote code execution bug in PeopleSoft Enterprise PeopleTools rated 9.8 out of 10.
About this happening: Oracle PeopleSoft PeopleTools CVE-2026-35273 is a critical zero-day RCE affecting PeopleSoft Enterprise PeopleTools 8.61 and 8.62. Oracle released emergency mitigati...
Latest development: 29.06.2026 23:40
Nissan says it suffered a data breach affecting current and former employees after attackers exploited an Oracle PeopleSoft zero-day associated with CVE-2026-35273. Oracle informed Nissan that personnel records of hundreds of companies may have been obtained and that Nissan was specifically targeted, with potentially exposed data including contact details, banking information, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary data for employees in the United States, Canada, Mexico, and Brazil.
Nottingham University data publication on ShinyHunters leak site
Data Leak
H score68
First: 10.06.2026 21:31
Last: 10.06.2026 21:31
Sources 1
How related:
In a post on their dark web leak site, the cybercrime group claims to have stolen over 40GB of documents containing student finance data, billing and payment information, credit card and payment details, and campus portal exports from the University of Nottingham and its Malaysia and China campuses
About this happening:
Nottingham University data was published on the ShinyHunters leak site after the group claimed access to the university’s student records system. The exposed material...
Nottingham University data publication on ShinyHunters leak site
Data LeakHow related: In a post on their dark web leak site, the cybercrime group claims to have stolen over 40GB of documents containing student finance data, billing and payment information, credit card and payment details, and campus portal exports from the University of Nottingham and its Malaysia and China campuses
About this happening: Nottingham University data was published on the ShinyHunters leak site after the group claimed access to the university’s student records system. The exposed material...
Timeline
-
11.06.2026 10:27 1 articles · 1mo ago
ShinyHunters claims responsibility for the University of Nottingham breach
Attribution UpdateShinyHunters claimed responsibility for unauthorized access to the University of Nottingham's student records system and shared an archive of allegedly stolen documents as proof.
Show sources
- Nottingham University data breach affects over 450,000 students — www.bleepingcomputer.com — 11.06.2026 10:27
-
11.06.2026 10:27 1 articles · 1mo ago
ShinyHunters says it stole over 40GB from University of Nottingham systems
Victim Impact UpdateShinyHunters said it stole over 40GB of documents from the University of Nottingham and its Malaysia and China campuses, including student finance data, billing and payment information, credit card and payment details, campus portal exports, and personal data such as names, home addresses, IP addresses, phone numbers, and dates of birth.
Show sources
- Nottingham University data breach affects over 450,000 students — www.bleepingcomputer.com — 11.06.2026 10:27
-
11.06.2026 10:27 3 articles · 1mo ago
University of Nottingham confirms student records access and reports the breach
Initial DisclosureThe University of Nottingham said a well-known cybercriminal group accessed its student record system, exposed a significant amount of data affecting current students and alums, and reported the incident to Action Fraud and the Information Commissioner's Office; Have I Been Pwned later estimated the breach affects 454,600 former and current students.
Show sources
- Nottingham University data breach affects over 450,000 students — www.bleepingcomputer.com — 11.06.2026 10:27
- Nottingham University data breach affects over 450,000 students — www.bleepingcomputer.com — 11.06.2026 10:27
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities — thehackernews.com — 11.06.2026 23:29