---
title: "University of Nottingham student-record-system incident"
description: "Evidence-backed account of University of Nottingham student-record-system incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/university-of-nottingham-student-record-system-incident-2026"
markdown_url: "https://www.ally.security/incidents/university-of-nottingham-student-record-system-incident-2026.md"
stix_url: "https://www.ally.security/incidents/university-of-nottingham-student-record-system-incident-2026/stix.json"
---

# University of Nottingham student-record-system incident

External-party access to a significant amount of data in the university's student record system. A verified HIBP corpus associated with the student-record-system incident, including education, contact, demographic, disability, and passport-related fields.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** HIBP associates its verified corpus with the university-confirmed student-record-system incident; detailed fields and corpus count are HIBP-specific.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

An external party accessed a significant amount of data in the [University of Nottingham](https://www.nottingham.ac.uk/) student record system. [2](#source-2)

## Impact

A verified HIBP corpus associated with the student-record-system incident, including education, contact, demographic, disability, and passport-related fields. [1](#source-1)

Documented data types include:

- Disability and special-education information — Disability information listed by HIBP; field presence can vary by record. [1](#source-1)
- Contact information — Email, phone, and physical-address fields listed by HIBP; field presence can vary by record. [1](#source-1)
- Education records — Academic enrolment and fee-payment information listed by HIBP; the university statement identifies the student record system but does not enumerate these fields. [1](#source-1)
- Passport numbers — Passport numbers listed by HIBP; no claim that every record included a passport number. [1](#source-1)
- Demographic information — Gender, ethnicity, citizenship-status, and related demographic fields listed by HIBP; no claim that each record contained every field. [1](#source-1)

A cited record reports 454,635 records (Unique email addresses in HIBP's verified corpus; not a university-confirmed count of affected people, students, alumni, applicants, accounts, or total rows; as of 2026-06-10). [1](#source-1)

The university identified current students and alumni as the two impacted groups, said it contacted affected people directly, and reported working with Action Fraud, the Information Commissioner's Office, and other regulators. [2](#source-2)

The university said an external third party accessed a significant amount of data in its student record system. [2](#source-2)

## Timeline

### June 9, 2026 — Documented event

HIBP's day-level BreachDate; the university statement confirms the incident but does not identify the access start, discovery, or containment date. [1](#source-1)

### June 10, 2026 — Public disclosure

External-party access to a significant amount of data in the university's student record system. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

HIBP marked the University of Nottingham incident record verified and not fabricated. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/university-of-nottingham-student-record-system-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### University of Nottingham breach record

advisory · Have I Been Pwned · Jun 10, 2026

<https://haveibeenpwned.com/api/v3/breach/UniversityOfNottingham>

<a id="source-2"></a>

### Student and alumni data has been compromised in a data security incident

official · The University of Nottingham · Jun 10, 2026

<https://www.nottingham.ac.uk/currentstudents/news/student-and-alumni-data-has-been-compromised-in-a-data-security-incident>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 90% confidence · current**  
   June 2026 University of Nottingham cyber incident: University of Nottingham student and alumni data corpus
2. **Exposed Data Category · 90% confidence · current**  
   University of Nottingham student and alumni data corpus: Disability and special-education information
3. **Exposed Data Category · 90% confidence · current**  
   University of Nottingham student and alumni data corpus: Contact information
4. **Affected Organization · 100% confidence · current**  
   June 2026 University of Nottingham cyber incident: The University of Nottingham
5. **Resulted In · 100% confidence · current**  
   June 2026 University of Nottingham cyber incident: The university identified current students and alumni as the two impacted groups, said it contacted affected people directly, and reported working with Action Fraud, the Information Commissioner's Office, and other regulators.
6. **Exposed Data Category · 90% confidence · current**  
   University of Nottingham student and alumni data corpus: Education records
7. **Exposed Data Category · 90% confidence · current**  
   University of Nottingham student and alumni data corpus: Passport numbers
8. **Disclosed At · 100% confidence · current**  
   June 2026 University of Nottingham cyber incident: 2026-06-10
9. **Exposed Record Count · 100% confidence · current**  
   University of Nottingham student and alumni data corpus: 454,635 record
10. **Exposed Data Category · 90% confidence · current**  
   University of Nottingham student and alumni data corpus: Demographic information
11. **Resulted In · 100% confidence · current**  
   University of Nottingham student and alumni data corpus: HIBP marked the University of Nottingham breach record verified and not fabricated.
12. **Occurred At · 90% confidence · current**  
   June 2026 University of Nottingham cyber incident: 2026-06-09
13. **Resulted In · 100% confidence · current**  
   June 2026 University of Nottingham cyber incident: The university said an external third party accessed a significant amount of data in its student record system.

</details>
