Ransomware victim disclosure
← All victimsUniversity of Nottingham
listed as nottingham.ac.uk · Claimed by Shinyhunters · listed 4 days ago
Status timeline
- ListedJun 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Education
- Listed on leak site
- Jun 9, 2026
About the victim
AI dossier — public-source company profileThe University of Nottingham is a major UK-based research university ranked in the top 20 universities in the UK and top 100 globally (QS 2026). It operates multiple campuses including locations in Malaysia and China, offering undergraduate, postgraduate, and research degree programmes alongside research and innovation services.
- Industry
- Higher Education & University Services
- Address
- Nottingham, United Kingdom (with campuses in Malaysia and China)
- Employees
- 3000-4000
- Founded
- 1928
Attack summary
Severity: critical — Confirmed exfiltration and publication of 19+ GB of sensitive financial and personal data including credit card details, student finance information, and PII (names, addresses, phone numbers, DoB) affecting a major educational institution with thousands of students and staff across multiple countries. Financial and identity theft risk is substantial.ShinyHunters claims to have exfiltrated over 40 GB (compressed to 19+ GB) of billing, payment, and student finance records from the University of Nottingham and its international campuses. The group asserts access to credit card details, payment information, student finance data, and campus portal exports containing personal identifiers.
Data the group says was taken
AI dossier — extracted from the leak post- billing and payment records
- credit card and payment details
- student finance data
- campus portal exports
- payer contact information
- transaction records
- IP addresses
- full names
- home addresses
- postcodes
- email addresses
- phone numbers
- dates of birth
- internal campus data
What the group claims
Over 40 GB of billing and payment records, credit card and payment details, student finance data, and campus portal exports from the University of Nottingham and its Malaysia and China campuses was compromised, including payer contact information, transaction amounts, IP addresses, full names, home addresses, postcodes, email addresses, phone numbers, dates of birth, and other internal campus data. | Size: 19GB+ (compressed) | Updated: 10 June 2026 | SHA256: d3aaaf06dd857deec3866072cc2876780623d880992e8d735094db4779535873
Sources
- Victim sitenottingham.ac.uk
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

