Personal, financial, and contact information has been compromised during exam season
14:54, 10 Jun 2026Updated 16:53, 10 Jun 2026

The University of Nottingham has taken the impacted system offline to conduct an investigation(Image: Joseph Raynor/ Reach PLC)
The University of Nottingham has been rocked by a major cyberattack that has exposed students’ personal and financial data and could disrupt exam marking.
Hackers gained access to the Russell Group university’s student records system at the end of May, according to staff, potentially exposing their contact information, course information, financial details stored within the software, and personal information like NI numbers and protected characteristics.
The Nottingham Post understands the data breach into the Campus Solutions platform by a group of cybercriminals, the Shinyhunters, was only detected on Tuesday, June 9.
Following the attack, the university took the system offline to conduct an investigation, resulting in disruption to student exam marking, according to workers.
A University of Nottingham spokesperson said: “The University of Nottingham has been the victim of a cyber incident and a significant amount of data in our student record system has been accessed by a well-known cybercriminal group.
“We are working with the third party that maintains the platform to lead a forensic investigation.
“We understand that those affected will have concerns about what this means for their personal data and we will be offering advice and support to our students as we learn more.
“We take the privacy and security of data that we hold seriously, and we have reported this incident to Action Fraud and the Information Commissioner’s Office.
“The university will continue to provide them with further information as our investigation progresses.”
An email sent to impacted students by the university warned them to be vigilant on “unexpected or suspicious communication”, particularly requesting financial information.
In the email Jason Carter, the university’s chief governance and risk officer, described the breach as a “serious incident”, said he was “deeply sorry” and asked affected people to change passwords.
Asked what information the Campus Solutions software stored, one staff member simply replied “everything”.
“I would like to think a good, effective organisation would notice if a major thing like this happened. You’d hope it wouldn’t take 10 days to notice.”
The employee added that he believed the data of thousands of people had been compromised.
If problems with the hacked software continued into next week this would be “hugely disruptive” to exam marking, they added.
Libby Warren, a former University of Nottingham student who graduated in 2024, was one of the many people who received a notice from her alma mater on Wednesday afternoon.
The 25-year-old said she was “very concerned” by the data breach, as she did not know what data of hers had been exposed.
“I’m not even sure why they still have my data,” she added.
The Information Commissioner’s Office, which investigates data breaches, said the university had reported the incident and added “we are assessing the information provided”.
The National Crime Agency told the Nottingham Post it was also aware of the breach.
“We are aware of an incident affecting the University of Nottingham and are working alongside partners to better understand the impact,” a NCA spokesperson said.