Investigation · Student & Alumni Data

University of Nottingham Data Breach Investigation

Hall Attorneys is evaluating potential claims after a June 2026 University of Nottingham student-record breach affecting current students and alumni and involving 454,635 indexed accounts.

Verified indexed count
454,635

unique email addresses listed by HIBP

Reported breach date
June 9, 2026

date assigned by HIBP

Listed data types
15

academic, identity, contact, and profile fields

Answer at a glance

What happened in the University of Nottingham data breach?

The University of Nottingham confirmed that a significant amount of data in its student record system was accessed by a cybercriminal group. The university reported the incident to Action Fraud and the UK Information Commissioner's Office.

Have I Been Pwned says tens of gigabytes of data were later published online and lists 454,635 unique email addresses. The university's student notice says current students and alumni were affected.

The breach is widely linked to the ShinyHunters extortion campaign. The information associated with a particular person may vary, and the indexed account count is not necessarily a count of distinct people.

This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.

  1. Reported breach and publication date

    HIBP assigns June 9 as the breach date. Mandiant later reported that stolen organization data connected with the broader PeopleSoft campaign was published on the ShinyHunters data-leak site that day.

  2. Breach added to Have I Been Pwned

    HIBP added a verified entry listing 454,635 unique email addresses and 15 compromised data categories.

  3. University confirms student-record access

    The university confirmed the attack in public reporting, said its student record system was accessed, and reported the incident to Action Fraud and the ICO.

Reported data categories

What information was involved?

HIBP lists 15 categories in the indexed dataset. Several are sensitive student-profile and identity fields that can create risks beyond ordinary email phishing.

Important distinction

The source record describes data at the dataset level. It does not establish that every listed category was present for every account or that 454,635 accounts represent 454,635 distinct people.

Academic and payment records
Academic records, purchases, and fee-payment information
Identity and citizenship
Names, dates of birth, citizenship statuses, genders, and passport numbers
Sensitive profile details
Disabilities, ethnicities, and salutations
Contact and account data
Email addresses, usernames, IP addresses, phone numbers, and physical addresses

Who may want to contact us

Current students, alumni, and notice recipients

The university has said the event affects current students and alumni. The investigation focuses on those groups and anyone whose sensitive student-record information may have been involved.

Current University of Nottingham students who received an incident communication

Alumni whose historical student records or email addresses may appear in the dataset

People whose passport, disability, ethnicity, academic, payment, or contact information may have been involved

People experiencing university-themed phishing, impersonation, identity misuse, fraud, expense, or lost time

What to preserve

Keep university notices, identity records, and evidence of misuse

Preserve relevant records, but do not send passwords, complete financial-account numbers, passport images, other government identification, or unredacted credit reports through ordinary website forms.

Notices and monitoring offers

Keep the complete University of Nottingham notice, envelope, email, enrollment instructions, deadline, and any later updates.

Relationship records

Preserve records showing your student, alumni, applicant, or other relationship with the university, including dated account, enrollment, employment, alumni, transaction, or correspondence records.

Information held about you

Save records or dated screenshots showing the contact, identity, academic, employment, financial, or profile information the organization held about you.

Suspicious communications

Keep phishing emails, texts, calls, password-reset messages, account alerts, or other communications that use organization-specific details.

Credit and account records

Preserve credit alerts, unfamiliar-account notices, fraud reports, freeze confirmations, monitoring results, and relevant financial correspondence.

Time, expenses, and harm

Track time spent securing accounts or responding to misuse, along with out-of-pocket costs, lost funds, denied credit, or other concrete effects.

Investigation focus

Issues under review

Hall Attorneys is reviewing the student-record access, the reported publication, the data involved, the university's notice and support process, and harms reported by affected people.

  1. Which student-record platform, systems, and campuses were accessed
  2. When access began, how it occurred, and when the university and its platform provider detected it
  3. How many distinct current students, alumni, applicants, employees, or other people were affected
  4. Which of the 15 indexed categories were associated with each person
  5. Whether affected people received complete, timely, and jurisdiction-appropriate notice and support
  6. Whether the incident led to targeted phishing, identity-document misuse, fraud, financial loss, monitoring costs, or time loss

Public records reviewed

Sources for the University of Nottingham incident

The sources below include the university's notice, HIBP's dataset description, and contemporaneous security reporting. Findings may change as the university and the ICO continue their work.

Contact the firm

Were you affected by the University of Nottingham breach?

Contact Hall Attorneys with your general relationship to the university, whether you received notice, your U.S. state or country, and a summary of suspicious activity or loss. Do not include passwords, passport images, or full account numbers in an initial message.

Contact Hall Attorneys

Frequently asked questions

University of Nottingham breach FAQ

Is this a filed University of Nottingham data breach lawsuit?

No. This page describes an investigation by Hall Attorneys and does not state that the firm has filed a lawsuit concerning the University of Nottingham.

How many University of Nottingham accounts were affected?

Have I Been Pwned lists 454,635 unique email addresses. That figure does not necessarily equal the number of distinct people.

Who did the university say was affected?

The university's notice says current students and alumni were affected. Public reporting also describes access to the student record system.

What information was reportedly exposed?

HIBP lists academic records, citizenship, birth dates, disabilities, email addresses, ethnicities, genders, IP addresses, names, passport numbers, phone numbers, physical addresses, purchases, salutations, and usernames.

Does Hall Attorneys represent people outside the U.S.?

Jurisdiction and available claims depend on where a person lives, where conduct occurred, and other facts. A person may contact the firm with their location and general circumstances so the firm can evaluate next steps.

Attorney Advertising

Hall Attorneys is not affiliated with University of Nottingham or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.