EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-university-of-nottingham-breach
030/430

File EL-0401HighContainedData Breach / Ransomware / Extortion with Data Exfiltration

University of Nottingham Data Breach

Also filed as Nottingham PeopleSoft Breach · ShinyHunters University of Nottingham Hack

ShinyHunters exploited a critical zero-day vulnerability in Oracle PeopleSoft (Campus Solutions) to access and exfiltrate a significant volume of student and alumni records from the University of Nottingham.

  • #education-data
  • #pii
  • #student-records
  • #alumni-data
  • #financial-information
  • #passport-numbers
  • #peoplesoft
  • #higher-education
Notoriety8/10
Event
9 Jun 2026
Disclosed
10 Jun 2026
Target
University of Nottingham
Actor
ShinyHunters
Scale
455K people
Status
Contained

01Summary

On 9 June 2026 the University of Nottingham detected unauthorised activity in its Campus Solutions (PeopleSoft) student records platform and took systems offline. Forensic investigation determined attackers exploited a vulnerability in Oracle WebLogic supporting the platform (part of the broader CVE-2026-35273 PeopleSoft zero-day campaign). ShinyHunters claimed responsibility, stating they stole approximately 40 GB of data including student finance, billing, payment, and portal information. Have I Been Pwned later indexed ~454,600–455,000 unique email addresses with extensive personal fields. The university stated it did not receive a direct ransom demand. Data was published by the group.

02Background

Campus Solutions / PeopleSoft is a widely used student information system. The University of Nottingham is a major UK Russell Group institution with international campuses.

03Key revelations

  1. 01Part of a large-scale ShinyHunters campaign exploiting a critical PeopleSoft zero-day that affected over 100 organisations.
  2. 02Sensitive fields including passport numbers, ethnicity, and disability data were among those exposed.

04Technical analysis

Exploitation of CVE-2026-35273 (critical unauthenticated RCE in Oracle PeopleSoft / related WebLogic components). Part of a wider ShinyHunters campaign that hit ~100 organisations / ~300 instances between late May and early June 2026, with heavy concentration in higher education.

Attack vector
Exploitation of Oracle PeopleSoft zero-day (CVE-2026-35273)
Attack method
Remote code execution, data exfiltration, and public leak
Initial access
Exploitation of Public-Facing Application
Exfiltration
Bulk data extraction and compression (zstd reported in campaign)

Vulnerabilities exploited

  • CVE-2026-35273 (Oracle PeopleSoft / WebLogic)

05Threat actor

ShinyHunters is a prolific cybercriminal/extortion group known for large-scale data theft and 'pay or leak' operations, frequently targeting enterprise platforms and high-value datasets.

Aliases

  • SH
  • UNC6240

Attribution sources

  • ShinyHunters leak site claims
  • University of Nottingham statements
  • Mandiant / Google Threat Intelligence
  • Have I Been Pwned
  • Media reports

06Victims and impact

Additional victims

  • Current and former students, alumni, and some applicants (including Malaysia and China campuses claimed)

Countries affected

  • United Kingdom
  • Malaysia
  • China

07Data exposed

Data types

  • PII
  • Names
  • Email addresses
  • Physical addresses
  • Phone numbers
  • Dates of birth
  • Passport numbers
  • Ethnicity
  • Disability information
  • Academic records
  • Enrolment and fee payment data
  • Financial / billing information

08Financial damage

Operational disruption to student systems; forensic and notification costs; potential regulatory and reputational impact.

09Timeline

  1. 2026-05-27Start of observed exploitation window for CVE-2026-35273 (per Mandiant).
  2. 2026-06-09University detects unauthorised activity and takes systems offline.
  3. 2026-06-10ShinyHunters claims and begins publishing data; university confirms incident.

10Reaction and fallout

Public reaction

Concern over exposure of highly sensitive student and alumni data, including protected characteristics and identity documents.

11Legal

Criminal investigation by East Midlands Special Operations Unit; university investigation ongoing at time of updates.

12Aftermath

Security improvements

  • Affected systems taken offline immediately
  • Forensic investigation with external specialists
  • Broader Oracle mitigations issued for the vulnerability

13Significance and legacy

Significance

High-profile UK higher-education victim of the 2026 ShinyHunters Oracle PeopleSoft zero-day campaign, notable for the sensitivity of the data fields exposed.

14Disclosure and media

Authentication
Data published on ShinyHunters leak site and indexed by Have I Been Pwned

Publishing organisations

  • BBC
  • The Register
  • Have I Been Pwned
  • Ars Technica
  • University of Nottingham official updates

15Related files

Related events

  • 2026 ShinyHunters Oracle PeopleSoft zero-day campaign (CVE-2026-35273)

16Field notes

  1. 01Approximately 455,000 unique email addresses indexed by Have I Been Pwned.
  2. 02Claimed data volume ~40 GB; included fields such as passport numbers and disability information.

17Resolution

Systems taken offline on discovery. Data was published by ShinyHunters. Full impact assessment and support for affected individuals continued after disclosure.

18Sources

Official documents

  • University of Nottingham cyber incident updates

References

  1. [1]University of Nottingham official statements
  2. [2]Have I Been Pwned
  3. [3]BBC
  4. [4]The Register
  5. [5]Mandiant / Google reporting on the wider campaign
Fact sheetEL-0401

Dates

Event
9 Jun 2026
Started
27 May 2026
Ended
9 Jun 2026
Discovered
9 Jun 2026
Disclosed
10 Jun 2026
Ongoing
No

Target

Organisation
University of Nottingham
Type
University / Higher Education
Sector
Education
Country
United Kingdom

Actor

Name
ShinyHunters
Type
Criminal Gang
Motivation
Financial gain through data theft and extortion.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
455,000
Records
455,000
Volume
Approximately 40 GB (claimed)
Sensitivity
High
Published
Yes

Money

Crypto
Likely (standard for ShinyHunters extortion)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.