University of Nottingham Data Breach
June 2026. The same group behind the Canvas/Instructure incident hit a major university six weeks later through a different door. One threat actor, two education-sector victims, two entry points. Education is a named, repeat target.
We include this UK higher-ed incident because of one fact: it was the same threat actor as the Canvas/Instructure breach. For a US K-12 reader, the throughline is what matters, not the campus.
TL;DR
In early June 2026, the cybercrime group ShinyHunters breached the University of Nottingham's student record systems and posted stolen data to its dark-web extortion site. The university publicly confirmed the incident on June 10, 2026, acknowledging that "a significant amount" of current and former student data was accessed. Have I Been Pwned cataloged 454,600 affected accounts. ShinyHunters claimed roughly 40GB of data spanning the university's UK, Malaysia, and China campuses. This is the same group behind the 2026 Instructure/Canvas incident.
Timeline
- ~June 9, 2026: Attack detected; affected systems taken offline. The original intrusion date has not been stated.
- June 10, 2026: The university confirms the incident. ShinyHunters claims responsibility and begins posting data. Have I Been Pwned adds the breach.
- June 11, 2026: Trade and mainstream press report (BleepingComputer, The Register, The Record, SecurityWeek).
Confirmed exposed
- Per the published data (Have I Been Pwned analysis): email addresses, names, usernames, dates of birth, addresses, phone numbers, genders, ethnicities, disabilities, citizenship statuses, passport numbers, IP addresses, academic records, and purchases
- University framing: contact info, course/university details, financial information, and personal data "may have been accessed," including National Insurance numbers and payment details, pending forensics
Confirmed not exposed
- The university has not confirmed a victim count or a final exposed-fields list; forensics were ongoing at disclosure
Attacker-claimed specifics (credit card details, billing records, ~40GB volume) come from the ShinyHunters extortion site, not university confirmation. The 454,600 figure is derived by Have I Been Pwned from partially published data, not a university-confirmed count.
The ShinyHunters connection
ShinyHunters claimed Nottingham on the same dark-web extortion site, using the same playbook, as the Canvas/Instructure incident. Two education-sector victims six weeks apart, two different entry points: Canvas's Free-For-Teacher account program in May, and reporting attributes Nottingham to Oracle PeopleSoft vulnerabilities as part of a campaign hitting more than 100 organizations. Security researchers framed the Canvas campaign as ShinyHunters putting the education sector "in the crosshairs."
Why it matters
The same adversary that hit Canvas, the platform sitting in thousands of US districts, emptied a major university's student record system weeks later. ShinyHunters is working through the education sector and does not need the same door twice. The data your district hands to vendors (student IDs, dates of birth, contact info, financial records) is the exact category exposed in both incidents. Knowing which vendors hold which data is how a district shortens its reaction time when the next name on the list is one of its own.
Sources
- The Record — University of Nottingham confirms cyber incident as ShinyHunters claims data theft (2026-06-11)
- BleepingComputer — Nottingham University data breach affects over 450,000 students (2026-06-11)
- The Register — ShinyHunters raids Nottingham Uni for student, alumni data (2026-06-11)
- Hackread — ShinyHunters University of Nottingham student data leak (2026-06-11)
- Have I Been Pwned — University of Nottingham breach record (added 2026-06-10, 454.6k accounts)
- SecurityWeek — University of Nottingham Confirms Breach After Hackers Leak Data (2026-06)
- BBC News — Students data taken in major university cyber-attack (2026-06-10)
This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].