University of Nottingham cyberattack compromised 450,000 e-mail accounts

Cybersecurity
Share


The University of Nottingham has confirmed that a major cyberattack targeting its student record platform has potentially compromised 450,000 email addresses.

The breach occurred on June 9, when attackers targeted the university’s “Campus Solutions” management system. A forensic investigation revealed that hackers exploited a security vulnerability within a third-party software platform called Oracle WebLogic.

This flaw allowed unauthorised remote code execution, giving external actors access to core parts of the university’s network infrastructure.

The university is operating under the precautionary assumption that the breach impacts current students, applicants and a number of alumni. Crucially, the impact extends beyond the UK, with student records from the university’s international campuses in Malaysia and China also believed to be caught up in the breach.

While technicians are still mapping the exact parameters of the exposed data fields, a hacking group called ShinyHunters has claimed responsibility for the attack on its dark web leak site, claiming to have stolen over 40GB of material. Data repositories analysing the leak report that the exposed files contain highly sensitive information, including:

  • Full names, usernames, postal addresses, phone numbers, staff IDs and student identification numbers.

  • Financial records, including student finance data, billing histories, and payment or credit card details.

  • Dates of birth, nationalities, National Insurance numbers, passport numbers, and citizenship status.

  • Personal demographic data, including ethnicity, disabilities, and sexual orientation.

The university has since contained the incident and taken the affected platform offline while IT teams secure and rebuild the system.

Ransom status and investigation

While cybersecurity attacks of this nature typically involve extortion, both the university and student media reports confirm that Nottingham has received no direct request for a financial ransom from the hackers.

Jason Carter, the university’s Chief Governance and Risk Officer, clarified in an email to students that the event was “not a ransomware attack” nor an “accidental disclosure,” meaning the data was copied and leaked rather than encrypted or deleted. Under UK government guidelines, public institutions are prohibited from paying cyber ransoms.

The East Midlands Special Operations Unit (EMSOU) has launched a formal criminal investigation into the incident, alongside oversight from the National Cyber Security Centre and the Information Commissioner’s Office (ICO).

A dedicated support helpline has been established for those affected. University officials are advising all students, applicants and alumni to actively monitor their financial accounts, remain vigilant against phishing attempts and update their digital credentials immediately.

For latest tech stories go to TechDigest.tv


Discover more from Tech Digest

Subscribe to get the latest posts sent to your email.