Summary
- Environment: HIBP associates its verified corpus with the university-confirmed student-record-system incident; detailed fields and corpus count are HIBP-specific.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
An external party accessed a significant amount of data in the University of Nottingham student record system. [2]
Impact
A verified HIBP corpus associated with the student-record-system incident, including education, contact, demographic, disability, and passport-related fields. [1]
Documented data types include:
- Disability and special-education information — Disability information listed by HIBP; field presence can vary by record. [1]
- Contact information — Email, phone, and physical-address fields listed by HIBP; field presence can vary by record. [1]
- Education records — Academic enrolment and fee-payment information listed by HIBP; the university statement identifies the student record system but does not enumerate these fields. [1]
- Passport numbers — Passport numbers listed by HIBP; no claim that every record included a passport number. [1]
- Demographic information — Gender, ethnicity, citizenship-status, and related demographic fields listed by HIBP; no claim that each record contained every field. [1]
A cited record reports 454,635 records (Unique email addresses in HIBP’s verified corpus; not a university-confirmed count of affected people, students, alumni, applicants, accounts, or total rows; as of 2026-06-10). [1]
The university identified current students and alumni as the two impacted groups, said it contacted affected people directly, and reported working with Action Fraud, the Information Commissioner’s Office, and other regulators. [2]
The university said an external third party accessed a significant amount of data in its student record system. [2]
Timeline
Documented event
HIBP’s day-level BreachDate; the university statement confirms the incident but does not identify the access start, discovery, or containment date.
[1]Public disclosure
External-party access to a significant amount of data in the university’s student record system.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
