University of Nottingham data breach exposes student and alumni records

Hackers accessed student records in the University of Nottingham data breach, including financial information.

University of Nottingham data breach involving student records, financial information and cyber attack investigation

The University of Nottingham has confirmed that an external third party accessed a significant amount of data in its student record system during a cyber incident.

The university said the incident affected current students and alums and that it is working with the third-party provider that maintains the affected platform to support a forensic investigation. It has reported the incident to Action Fraud and the Information Commissioner’s Office.

The university has not publicly attributed the attack, but the ShinyHunters extortion group has claimed responsibility. Have I Been Pwned said the breach affected 454,600 accounts and involved tens of gigabytes of data, which was later published online.

According to Have I Been Pwned, the exposed data included names, email addresses, phone numbers, physical addresses, passport numbers, citizenship statuses, dates of birth, academic records, ethnicity, disability information, IP addresses and information relating to enrolments and fee payments.

The university told affected individuals that it was operating on the precautionary assumption that contact information, university-related details, financial information and personal information may have been accessed.

The breach creates risks of identity theft, fraud and follow-up phishing attacks, particularly where exposed records include identity documents, financial data and sensitive personal characteristics.

The University of Nottingham Students’ Union advised students to monitor university communications, use the dedicated support line and remain cautious about unexpected emails, messages or calls.

Why does it matter?

The breach highlights the scale of cyber risk facing higher education institutions, which hold large volumes of sensitive personal, financial and academic data. Exposure of passport numbers, contact details, protected characteristics and payment-related information can create long-term risks for students and alums. The incident also points to the importance of third-party platform security and clear breach communication, especially when student record systems are involved.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!