Notices and monitoring offers
Keep the complete University of Nottingham notice, envelope, email, enrollment instructions, deadline, and any later updates.
Hall Attorneys is evaluating potential claims after a June 2026 University of Nottingham student-record breach affecting current students and alumni and involving 454,635 indexed accounts.
unique email addresses listed by HIBP
date assigned by HIBP
academic, identity, contact, and profile fields
Answer at a glance
The University of Nottingham confirmed that a significant amount of data in its student record system was accessed by a cybercriminal group. The university reported the incident to Action Fraud and the UK Information Commissioner's Office.
Have I Been Pwned says tens of gigabytes of data were later published online and lists 454,635 unique email addresses. The university's student notice says current students and alumni were affected.
The breach is widely linked to the ShinyHunters extortion campaign. The information associated with a particular person may vary, and the indexed account count is not necessarily a count of distinct people.
This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.
HIBP assigns June 9 as the breach date. Mandiant later reported that stolen organization data connected with the broader PeopleSoft campaign was published on the ShinyHunters data-leak site that day.
HIBP added a verified entry listing 454,635 unique email addresses and 15 compromised data categories.
The university confirmed the attack in public reporting, said its student record system was accessed, and reported the incident to Action Fraud and the ICO.
Reported data categories
HIBP lists 15 categories in the indexed dataset. Several are sensitive student-profile and identity fields that can create risks beyond ordinary email phishing.
Important distinction
The source record describes data at the dataset level. It does not establish that every listed category was present for every account or that 454,635 accounts represent 454,635 distinct people.
Who may want to contact us
The university has said the event affects current students and alumni. The investigation focuses on those groups and anyone whose sensitive student-record information may have been involved.
Current University of Nottingham students who received an incident communication
Alumni whose historical student records or email addresses may appear in the dataset
People whose passport, disability, ethnicity, academic, payment, or contact information may have been involved
People experiencing university-themed phishing, impersonation, identity misuse, fraud, expense, or lost time
What to preserve
Preserve relevant records, but do not send passwords, complete financial-account numbers, passport images, other government identification, or unredacted credit reports through ordinary website forms.
Keep the complete University of Nottingham notice, envelope, email, enrollment instructions, deadline, and any later updates.
Preserve records showing your student, alumni, applicant, or other relationship with the university, including dated account, enrollment, employment, alumni, transaction, or correspondence records.
Save records or dated screenshots showing the contact, identity, academic, employment, financial, or profile information the organization held about you.
Keep phishing emails, texts, calls, password-reset messages, account alerts, or other communications that use organization-specific details.
Preserve credit alerts, unfamiliar-account notices, fraud reports, freeze confirmations, monitoring results, and relevant financial correspondence.
Track time spent securing accounts or responding to misuse, along with out-of-pocket costs, lost funds, denied credit, or other concrete effects.
Investigation focus
Hall Attorneys is reviewing the student-record access, the reported publication, the data involved, the university's notice and support process, and harms reported by affected people.
Public records reviewed
The sources below include the university's notice, HIBP's dataset description, and contemporaneous security reporting. Findings may change as the university and the ICO continue their work.
University of Nottingham ·
The university's notice for current students and alumni concerning the student-record incident and available support.
Read source: Student and alumni data compromised in a security incidentHave I Been Pwned ·
Lists 454,635 unique email addresses, 15 compromised data categories, and the reported public release.
Read source: University of Nottingham Data BreachThe Register ·
Contemporaneous reporting quoting the university's confirmation, describing the reported dataset, and noting reports to Action Fraud and the ICO.
Read source: ShinyHunters raids Nottingham Uni for student, alumni dataGoogle Threat Intelligence Group and Mandiant ·
Describes activity attributed to UNC6240, also known as ShinyHunters, observed from May 27 through June 9 and aligned with exploitation of CVE-2026-35273.
Read source: ShinyHunters Targets Education Sector with Oracle PeopleSoft ExploitContact the firm
Contact Hall Attorneys with your general relationship to the university, whether you received notice, your U.S. state or country, and a summary of suspicious activity or loss. Do not include passwords, passport images, or full account numbers in an initial message.
Frequently asked questions
No. This page describes an investigation by Hall Attorneys and does not state that the firm has filed a lawsuit concerning the University of Nottingham.
Have I Been Pwned lists 454,635 unique email addresses. That figure does not necessarily equal the number of distinct people.
The university's notice says current students and alumni were affected. Public reporting also describes access to the student record system.
HIBP lists academic records, citizenship, birth dates, disabilities, email addresses, ethnicities, genders, IP addresses, names, passport numbers, phone numbers, physical addresses, purchases, salutations, and usernames.
Jurisdiction and available claims depend on where a person lives, where conduct occurred, and other facts. A person may contact the firm with their location and general circumstances so the firm can evaluate next steps.
Attorney Advertising
Hall Attorneys is not affiliated with University of Nottingham or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.