The University of Nottingham confirmed that a cyber-attack hit its student record, which was claimed by infamous ransomware group ShinyHunters.
The cyber gang claimed it stole around 40 gigabytes of student data in the breach.
The University says that it is working with government bodies and third party agencies to mitigate the damage of the attack.
We are working to understand the data that has been accessed and have contacted those students and alumni affected directly. We are working closely with Action Fraud, the Information Commissioner’s Office, and other regulatory bodies,” the university said in a statement.
Upon detecting the breach, the Univeristy immediately took action to take affected systems offline.
ShinyHunters claimed that student data affected includes those on the university’s England, Malaysia, and China campuses. The group said that the 40 GB of data likely includes personal payment details from students like finance data and credit card information. Current students and alumni appear to be affected, according to the University, which said it contacted affected individuals.
The group warned that the “inevitable” would happen if a ransom was not paid for the data, though paying ransom is prohibtied for universities in the UK.
It has been reported that the attackers potentially lingered in the University of Nottingham’s systesm for over a week before they were detected, drawing scrutiny from cyber experts considering continued warnings to major insitutions to shore up their defences.
Recommended reading
- Report: Cyber Breaches Are Tanking Share Prices
- Human Error Costing UK Business Billions in Data Breach Losses
- European Commission Confirms Data Breach, ShinyHunters Claim Credit
- Inside the Aftermath: What Really Happens When You Get Hacked
- Report: 93% of Data Breaches Expose Financial Records
Following ShinyHunter’s announcement of the cyber-attack on Tuesday, Have I Been Pwned, the data breach tracker, shared the 10GB dataset that Shiny Hunters leaked, which included around 455k university email addresses.
“Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with extensive personal information, including names, addresses, phone numbers, ethnicities, disabilities, passport numbers, and information relating to academic enrolments and fee payments,” Have I Been Pwned said.





