University of Nottingham data breach: what to do now
By Jamie Hartwell · Updated 10 August 2026

The University of Nottingham confirmed on 10 June 2026 that an external third party accessed a significant amount of data in its student record system. Students and alumni are both affected. If you study there now, or ever have, treat your personal details as exposed until you hear otherwise. Here is what we know so far, and the five things worth doing today.
Already at uni?
Get our free At-Uni Pack: stretching the loan through the Jan-to-April gap, the hardship-fund route nobody mentions, signing a private let without losing your deposit, and getting council tax right. Twelve pages, checked for 2026/27.
We'll also send you one useful email every Tuesday. Unsubscribe in one click. Every signup is entered into the draw for a pair of Beats Studio Pro (£349 RRP), UK residents 18+. T&Cs.
What happened
The university says it has contacted everyone affected and reported the incident to the Information Commissioner's Office, the National Cyber Security Centre, the Office for Students, UCAS and Action Fraud. The affected systems were taken offline while it works out the full scope. So far, so standard.
The claim of responsibility is uglier. A criminal group called ShinyHunters says it took more than 40 GB of data, including billing records, card payment details and student finance information. The university has not confirmed that list, and groups like this exaggerate to push up the price of stolen data. They also sometimes tell the truth.
Update, 11 June: the stolen data has since been published online. Have I Been Pwned, the breach-notification service, catalogued it on 10 June and lists the exposed fields as names, dates of birth, home and email addresses, phone numbers, passport numbers, IP addresses, and academic and fee-payment records, alongside more sensitive details including ethnicity, citizenship and disability information, across roughly 455,000 accounts. Its summary does not list full payment-card numbers, but a date of birth and a passport number together are exactly what identity thieves want, which is why steps four and five below matter more than they might first look.
I read the University of Nottingham's own statement on Wednesday morning and checked the support line against the page rather than trusting screenshots of it. The number listed there is 0115 74 86500, and the statement asks you to keep checking your university email address for updates.
Nottingham is not even the only UK university breach this fortnight. The University of Oxford disclosed in early June that CareerConnect, the careers platform its students log into, was breached at its third-party provider Group GTI, and the same platform runs career hubs for King's College London and the University of Manchester. If you use a university careers site anywhere, the password advice below applies to you too.
Update, 10 August: Newcastle University has confirmed a breach of its own, and it is worth reading because it is the opposite kind to Nottingham's. Its statement says a configuration issue on an admissions system, spotted on 27 July, exposed contact details and nothing more: names, addresses, email addresses and phone numbers. No admissions records, no exam results, no bank details. It has told the ICO, and it tells affected people they need do nothing. ExfilSquad, the group behind it, advertises a much bigger haul of roughly 440,000 records including admissions data. I would still take the university's account over the criminals' number: theirs is unverified, and Newcastle says the admissions part is wrong.
Here is the timing bit I would diarise, because it is where these go wrong. The dangerous week is not this one. It is a month or two from now, once a contact list like that has been sold on and the scam texts start landing, addressed to you by name, mentioning Newcastle, timed for when you have half-forgotten there was a breach at all. The five steps below are built for a records leak like Nottingham's. A contact-details leak needs less than that: forward the dud emails to report@phishing.gov.uk, forward the scam texts to 7726, and keep it in your head that a real university or lender will never ring or email asking for a password or a payment. If one does, it is not them.
How do I know if I'm affected?
The university says affected students and alumni have been contacted directly. For current students that means your university inbox, so log in and check it, even if you normally let it pile up. Alumni are being emailed on whatever address the university still holds.
You can also check for yourself. Enter your university email address at Have I Been Pwned and it will tell you whether that address appears in the published Nottingham data. A match confirms you are affected. No match is reassuring rather than conclusive, because the service only covers the records that have been processed and loaded so far.

No email is not proof you're safe. Breach investigations widen as they go on. If you have ever paid the university for anything by card, tuition instalments, accommodation, gym membership, even a library fine, work on the careful assumption that those details are part of what was taken.
Five things to do today
Update, 28 June: the university has now arranged free identity protection for affected people, and it is worth taking up before you work through the steps below. It is a 12-month subscription to TransUnion's TrueIdentity service, which monitors your credit file and the dark web and alerts you to changes rather than leaving you to remember to check. Students and alumni can sign up by calling the university helpline on 0115 74 86500, 10am to 4pm Monday to Friday. Applicants are not covered yet, because the university says it is still working out whose data was caught up in the breach; if that is you, the five steps below are still your best protection. The free service does not replace those steps. It just does the watching for you for a year.
1. Treat every message about the breach as a possible fake
Whoever holds this data now has enough detail to write a very convincing email from "the university". The weeks after a breach are peak phishing season, because everyone affected is expecting official contact and clicks faster than usual. The university will not ask for your password, your card number or a payment to secure your account. Any message that does is a fake. Forward it to the NCSC's scam email reporting service and delete it.

2. Tell your bank if you've paid the university by card
The stolen set allegedly includes card payment details. Phone your bank, say your card may be caught up in the University of Nottingham breach, and let them decide whether to reissue it; a replacement arrives within a few days and costs you nothing. Then watch your statements over the next few months. Card fraud often starts with a small test payment of a pound or two, not a big obvious hit. Flag anything you don't recognise.

3. Change any password you reuse
The student record system holds, at minimum, your name, contact details and date of birth. If your university password is also your email password, or your banking password, change it now and switch on two-factor authentication while you're in the settings. Our cybersecurity guide for students walks through this step by step.
4. Check your credit report
Identity fraud shows up as credit applications you never made. Experian, Equifax and TransUnion all give you a free statutory credit report, which sounds like the stripped-down version of the paid product but shows every account and search a lender would see, just without the marketing. Pull one now and look for accounts or searches you don't recognise. Then check again in a month. Fraudsters often sit on stolen data for a while; a quiet first month proves nothing.
5. Consider Cifas Protective Registration
If you'd rather not rely on remembering to check, Cifas Protective Registration costs £30 and lasts two years. It puts a warning flag against your name in the National Fraud Database, which forces lenders to run extra identity checks before approving anything in your name. Look, paying £30 to clean up a leak you didn't cause stings. It is still far cheaper than untangling a loan someone else took out as you.
If your results are running late
Update, 28 June: the knock-on most students did not see coming is timing. With parts of the student record system taken offline while the breach is investigated, the Nottingham Post reported on 27 June that some finalists' results and degree confirmations are now expected to land later than usual, which matters because graduate schemes and entry-level jobs often want proof of your classification before they confirm a start date. You can still get your results; the worry is that they arrive after your peers' at other universities, leaving you at a disadvantage during the busiest grad-recruitment window of the year. Here is how to take the pressure off while you wait.
Tell the employer before they ask. If you have a job or scheme offer that is conditional on your final classification, email the recruiter now, briefly, to say your university has confirmed a delay to results because of a security incident outside your control, and that you will send proof the moment it lands. Most graduate employers deal with late results every single year and have a standard way to hold an offer open. The mistake is going quiet and letting them assume you have gone cold.
Ask the university for written confirmation of the delay. A short email or letter from the university stating that results are delayed, and roughly when to expect them, is exactly the document an employer's HR team needs to keep your offer open. Request it through the dedicated helpline on 0115 74 86500, open 10am to 4pm Monday to Friday, rather than chasing your individual tutor, who may not have the official line.
Use an interim transcript or predicted grade if you have one. If you need to show something now, a previous-year transcript or a predicted classification from your department can bridge the gap for many employers while the final result is processed. It is not the finished article, but it shows good faith and gives a recruiter something concrete to work with.
If a graduate offer is withdrawn purely because your university could not confirm results on time, that is worth raising with the university, because it is a direct consequence of the incident rather than anything you did. Keep your emails and any written confirmation of the delay; they are your evidence.
If something does go wrong
Report any actual fraud attempt to Action Fraud on 0300 123 2040 or through their website, and keep the crime reference number. Your bank and the university will both want it.
The Information Commissioner's Office is already involved and can investigate how the breach happened. If you think the university has mishandled your data, complain to the university first, then escalate to the ICO if the answer doesn't satisfy you. Our guide to student rights covers how complaints routes work.
Can you claim compensation?
Possibly, but go in with clear eyes. Under UK GDPR you can claim compensation if the breach caused you "material" damage (you actually lost money) or "non-material" damage (genuine distress). The catch is that you have to show that damage. The ICO cannot award you a penny: it can investigate and fine the university, but compensation only comes from the university agreeing to pay or from a court. A court can also order you to pay the other side's costs if you claim and fail to prove you were harmed.
You will already be seeing claims firms advertising "no win, no fee" group claims against the university. They are real, but they take a cut of any payout, often a quarter or more. You do not need one. Complaining to the ICO is free, and if you have a genuine loss you can claim directly. For most students with no actual financial loss, the protective steps above matter far more than chasing a speculative payout.
Where this stands, 21 July: the university's own incident page has not moved since 30 June. The helpline is still running on 0115 74 86500, 10am to 4pm Monday to Friday, the free TrueIdentity year is still open to affected students and alumni, and applicants are still outside it while the university works out whose data was caught. Nothing here has been superseded. We'll update the page again when the university does.
Reviewed · Editorial standards
Ask Jamie a question
If this guide didn't cover the thing you came for, ask. If enough people ask the same thing, it becomes a guide.
