More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
The University of Nottingham confirmed that a cybercriminal group accessed its student records system, exposing data on 454,600 current and former students. The breach hit the main campus plus Malaysia and China branches. Stolen files include 40 GB of student finance records, billing and payment details, credit card information, full names, home addresses, IP addresses, phone numbers and dates of birth. University officials say they’ve launched a forensic investigation with the third party that maintains the platform and reported the incident to Action Fraud and the UK Information Commissioner’s Office.
ShinyHunters, a well-known extortion gang, claimed responsibility on its dark-web leak site. The group says it used a “gadget chain” of zero-day flaws and older vulnerabilities to break into Oracle PeopleSoft instances. PeopleSoft is widely used for HR, finance, payroll and campus administration, and ShinyHunters has targeted more than 100 organizations worldwide in this campaign. The success of each attack varies depending on how individual PeopleSoft systems are configured.
Have I Been Pwned analyzed the data and confirmed the scale: nearly half a million records, including sensitive personal and academic details like ethnicities, disabilities, passport numbers, enrolment history and fee payments. Nottingham’s breach follows similar incidents at Oxford University’s CareerConnect platform on May 28 and Instructure’s Canvas LMS earlier this year, all tied to the same PeopleSoft-focused attacks. Oracle has yet to comment on whether any of its zero-day vulnerabilities are under active exploitation.
Questions about this article
No questions yet.