01Summary
On 9 June 2026 the University of Nottingham detected unauthorised activity in its Campus Solutions (PeopleSoft) student records platform and took systems offline. Forensic investigation determined attackers exploited a vulnerability in Oracle WebLogic supporting the platform (part of the broader CVE-2026-35273 PeopleSoft zero-day campaign). ShinyHunters claimed responsibility, stating they stole approximately 40 GB of data including student finance, billing, payment, and portal information. Have I Been Pwned later indexed ~454,600–455,000 unique email addresses with extensive personal fields. The university stated it did not receive a direct ransom demand. Data was published by the group.
02Background
Campus Solutions / PeopleSoft is a widely used student information system. The University of Nottingham is a major UK Russell Group institution with international campuses.
03Key revelations
- 01Part of a large-scale ShinyHunters campaign exploiting a critical PeopleSoft zero-day that affected over 100 organisations.
- 02Sensitive fields including passport numbers, ethnicity, and disability data were among those exposed.
04Technical analysis
Exploitation of CVE-2026-35273 (critical unauthenticated RCE in Oracle PeopleSoft / related WebLogic components). Part of a wider ShinyHunters campaign that hit ~100 organisations / ~300 instances between late May and early June 2026, with heavy concentration in higher education.
- Attack vector
- Exploitation of Oracle PeopleSoft zero-day (CVE-2026-35273)
- Attack method
- Remote code execution, data exfiltration, and public leak
- Initial access
- Exploitation of Public-Facing Application
- Exfiltration
- Bulk data extraction and compression (zstd reported in campaign)
Vulnerabilities exploited
- CVE-2026-35273 (Oracle PeopleSoft / WebLogic)
05Threat actor
ShinyHunters is a prolific cybercriminal/extortion group known for large-scale data theft and 'pay or leak' operations, frequently targeting enterprise platforms and high-value datasets.
Aliases
- SH
- UNC6240
Attribution sources
- ShinyHunters leak site claims
- University of Nottingham statements
- Mandiant / Google Threat Intelligence
- Have I Been Pwned
- Media reports
06Victims and impact
Additional victims
- Current and former students, alumni, and some applicants (including Malaysia and China campuses claimed)
Countries affected
- United Kingdom
- Malaysia
- China
07Data exposed
Data types
- PII
- Names
- Email addresses
- Physical addresses
- Phone numbers
- Dates of birth
- Passport numbers
- Ethnicity
- Disability information
- Academic records
- Enrolment and fee payment data
- Financial / billing information
08Financial damage
Operational disruption to student systems; forensic and notification costs; potential regulatory and reputational impact.
09Timeline
- 2026-05-27Start of observed exploitation window for CVE-2026-35273 (per Mandiant).
- 2026-06-09University detects unauthorised activity and takes systems offline.
- 2026-06-10ShinyHunters claims and begins publishing data; university confirms incident.
10Reaction and fallout
Public reaction
Concern over exposure of highly sensitive student and alumni data, including protected characteristics and identity documents.
11Legal
Criminal investigation by East Midlands Special Operations Unit; university investigation ongoing at time of updates.
12Aftermath
Security improvements
- Affected systems taken offline immediately
- Forensic investigation with external specialists
- Broader Oracle mitigations issued for the vulnerability
13Significance and legacy
Significance
High-profile UK higher-education victim of the 2026 ShinyHunters Oracle PeopleSoft zero-day campaign, notable for the sensitivity of the data fields exposed.
14Disclosure and media
- Authentication
- Data published on ShinyHunters leak site and indexed by Have I Been Pwned
Publishing organisations
- BBC
- The Register
- Have I Been Pwned
- Ars Technica
- University of Nottingham official updates
16Field notes
- 01Approximately 455,000 unique email addresses indexed by Have I Been Pwned.
- 02Claimed data volume ~40 GB; included fields such as passport numbers and disability information.
17Resolution
Systems taken offline on discovery. Data was published by ShinyHunters. Full impact assessment and support for affected individuals continued after disclosure.
18Sources
Official documents
- University of Nottingham cyber incident updates
References
- [1]University of Nottingham official statements
- [2]Have I Been Pwned
- [3]BBC
- [4]The Register
- [5]Mandiant / Google reporting on the wider campaign









