ShinyHunters has added the University of Nottingham to its data leak site, claiming to possess more than 40 GB of data allegedly stolen from the university and its campuses in Malaysia and China.
The threat actor claims the archive contains financial records, payment information, student finance data, campus portal exports, and other internal university information. The listing advertises a compressed archive exceeding 19 GB and was updated on June 10, 2026.
The University of Nottingham is a public research university headquartered in the United Kingdom with campuses spanning multiple countries and a student population of more than 50,000.
ShinyHunters alleges exposure of financial and student data
According to the leak site listing, the alleged dataset contains more than 40 GB of information originating from the University of Nottingham as well as its Malaysia and China campuses.
The threat actor claims the exposed data includes:
- Billing and payment records
- Credit card and payment information
- Student finance data
- Campus portal exports
- Payer contact information
- Transaction amounts
- IP addresses
- Full names
- Home addresses
- Postcodes
- Email addresses
- Phone numbers
- Dates of birth
- Additional internal campus data
The listing also references a downloadable archive and includes a SHA-256 checksum, suggesting the data has allegedly been packaged for distribution.
International campus claim remains unverified
The most notable aspect of the listing is its claim that the dataset includes information associated with multiple University of Nottingham campuses across different countries. However, no public evidence has been released that independently verifies the authenticity of the alleged data.
The posting does not disclose how access was allegedly obtained, when the purported intrusion occurred, or whether the information represents current university records.
Universities remain attractive targets for cybercriminal groups because they maintain large volumes of financial, personal, academic, and administrative information. Data involving payment systems and student financial records can present significant fraud and identity theft risks if exposed.
Recent education sector incidents covered by BreachNews include Evanston Township High School’s confirmed ransomware attack and the Canvas-related breach affecting schools across the United States, highlighting continued pressure on educational institutions.
University confirms student and alumni data was accessed
Update June 11, 2026: Following publication, the University of Nottingham confirmed that it was the victim of a cyber incident involving unauthorized access to data within its student record system.
In a public notice published on June 10, the university stated that “a significant amount of data” had been accessed by an external third party. The institution said two groups were affected by the incident: current students and alumni.
The university stated it is working to determine exactly what information was accessed and has contacted affected individuals directly. It also said it is working with Action Fraud, the Information Commissioner’s Office, and other regulatory bodies as part of its response.
The statement did not disclose how the intrusion occurred, whether the incident is connected to the claims made by ShinyHunters, or whether campuses outside the United Kingdom were affected.
While the university has confirmed unauthorized access to student records, BreachNews has not independently verified the specific data categories or volumes claimed by ShinyHunters, including the alleged 40 GB archive and references to financial and payment-related information.
The university said it will continue providing updates to affected students and alumni as its investigation progresses.












