University of Nottingham Student Data Breach
Coverage from SecurityWeek, Tech Jacks Solutions Security Command Center, and others

The University of Nottingham confirmed unauthorized access to a student records system affecting current students and alumni.
ShinyHunters claimed responsibility and published sample material, while third-party analysis indicated exposure of large volumes of email addresses and other personal data; the university and UK authorities are still assessing the precise scope. The incident highlights the sensitivity of education records, which can combine identity, contact, enrollment, and financial information across multiple campuses.
The incident is now associated with substantially larger, quantified exposure estimates and potentially extends across the university’s Malaysian and Chinese campuses. However, the figures remain provisional while the university and authorities determine the confirmed scope.
The story is now framed with greater uncertainty about how the intrusion occurred, while the previously reported scale, data specifics, and broader PeopleSoft campaign are no longer emphasized. The Office for Students is newly identified as a notified regulator.
