Menu
Browse

Cyber Incident Victim: University of Nottingham

Date

May 2026

Location

United Kingdom

Status

Ongoing

Updated

2026-07-31 00:59

Timeline
Occurred
May 2026
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Pending
Summary

ShinyHunters exploited an unpatched Oracle PeopleSoft zero‑day vulnerability to breach the networks of over a hundred organizations, with a significant portion belonging to the higher education sector. The group claimed to have stolen data from the University of Nottingham, leaking portions of the stolen student information and demanding extortion payments. Mandiant and Google Threat Intelligence Group identified the campaign, notified potentially affected entities, and noted that the activity remains ongoing despite the absence of a vendor patch.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

ShinyHunters began exploiting the Oracle PeopleSoft zero‑day vulnerability identified as CVE‑2026‑35273, which permits unauthenticated remote code execution and server takeover, with activity traced back to at least May 27 2026 according to Mandiant. Mandiant and the Google Threat Intelligence Group became aware of the campaign earlier in June 2026 while monitoring the group’s operations. The attackers claimed to have compromised more than one hundred organizations and started naming victims and publishing allegedly stolen data on a Tuesday in June. University of Nottingham was identified as one of the alleged victims and, on the following Wednesday, confirmed that a significant amount of student data had been stolen during the cyberattack after ShinyHunters leaked some of the school’s information. Oracle PeopleSoft PeopleTools, the affected suite, comprises more than forty tools used for human resources and customer relationship management.

Cyber Incident Image

Oracle disclosed the vulnerability and issued mitigation recommendations on the same Wednesday that the university made its confirmation, weeks after the initial intrusions had begun, although no patch had been released at that time. Google reported that it had alerted more than one hundred organizations about potentially vulnerable PeopleSoft endpoints in their environments but did not disclose how many of those entities were actually compromised. Mandiant’s chief technology officer noted that the extortion campaign remained active, with ShinyHunters sending extortion messages as recently as the day of the report. The majority of the potential victim pool is located in the United States, and approximately sixty‑eight percent of those targets belong to the higher education sector. This incident follows a similar zero‑day exploitation by the Clop ransomware group in Oracle E‑Business Suite less than a year earlier, which led to a data‑theft extortion effort that started in August and gained momentum in October.

Sources
Sources available to members
1 source