A threat actor operating as ShadowByt3$ claims to have breached Knottingham Trent University on 19 August 2026 through the host webapps.ntu.ac.uk, exfiltrating high-risk personal data including raw passport scans, dates of birth, home addresses, and full academic and employment histories. The claim surfaced publicly on 25 August 2026 via the actor's leak-site listing, tracked by Ransomware.live and republished by Hendry Adrian's ransom feed and Undercode News. Every source available for this brief is OTHER-tier: there is no university statement, no ICO filing, no national CERT advisory, and no vendor bulletin. Nothing here is confirmed by the victim, and the strongest single artefact is the extortion post itself, which Ransomware.live reproduces at length. Treat the entire incident as an unverified actor claim with unusually specific supporting detail.
What Happened
According to the leak-site description reproduced by Ransomware.live, the actor wrote: "We breached Knottingham trent University on August 19th 2026 by gaining access through webapps.ntu.ac.uk." The same posting states the actor notified the university, that the university acknowledged the breach internally, and that defenders then revoked the actor's access, but only after data had been taken. Hendry Adrian's writeup restates the same sequence: access to the university portal, data staged and exfiltrated, then lockout.
The timeline in the sources is internally inconsistent. Ransomware.live lists a "Discovered" timestamp of 2026-08-25 14:24 UTC and an "Est. attack date" of 2026-08-25, which contradicts the 19 August intrusion date asserted in the body of the actor's own post and repeated by Hendry Adrian. The most defensible reading is that 25 August is the date of public listing and automated discovery, not the date of compromise, and that 19 August is the actor's claimed intrusion date. No forensic source corroborates either.
Undercode News is explicit that this is an unverified third-party claim rather than a breach announcement, and notes that the allegation reached them via the X account "Cybersecurity News Everyday" with no technical evidence, no database sample, no CVE, no forensic report, and no independent confirmation attached. Hendry Adrian carries a matching disclaimer stating the post is based on public claims by the group and that accuracy cannot be confirmed.
There is also a naming problem defenders should not skip past. The actor and the trackers write "Knottingham Trent University", while Undercode News reports the target as Nottingham Trent University. The domain cited, ntu.ac.uk, belongs to Nottingham Trent University. The misspelling is most likely the actor's, propagated verbatim into automated trackers, but no source resolves the ambiguity, and Nottingham Trent University has said nothing publicly in any source reviewed here.
What Was Taken
No source gives a record count. Not one of the eight provides a figure for individuals affected, files exfiltrated, or data volume for this incident, and defenders should be sceptical of any downstream reporting that supplies one. What the sources do provide is a categorical inventory, consistent between Ransomware.live and Hendry Adrian:
- Passport numbers and full passport document details, taken from raw PDF scans of applicants' physical passports
- Dates of birth, described as visible on the main data profile screen
- Nationalities and countries of birth, drawn from passport logs and registration metadata
- Full legal names
- Personal email addresses exposed through the portal login view
- Mobile phone numbers from the dashboard contact view
- Permanent and correspondence home addresses at full street level, including house numbers, apartment complexes, districts, and postcodes
- Complete academic history from transcript PDFs and secondary school completion certificates, including exact grade percentages, modules studied, and prior school names
- Employment and professional history extracted from uploaded CV files
- Professional reference names taken from letters of recommendation
The Ransomware.live listing publishes named individuals, a personal email address, a mobile number, and residential locality and postcode data for addresses in Lucknow and Delhi. Wasteland is not reproducing those identifiers. Their presence matters analytically for two reasons: it suggests the compromised system is an applicant or admissions portal rather than a general student record system, and the Indian addresses point to international applicant records, a population that is disproportionately exposed to visa and immigration-themed fraud.
The actor frames the academic and employment material as the payload for social engineering rather than the prize itself, arguing in the listing that this context lets attackers "write highly convincing scam letters." That is an accurate read of the risk. Both Ransomware.live and Hendry Adrian record threats to leak the data and to damage the university's reputation if demands were not met.
Why It Matters
UK higher education is under sustained, compounding pressure, and this claim lands in the middle of a documented surge rather than as an isolated event.
Jisc's monitoring of its Janet Network, reported by The Tab, found more than 144,000 stolen username and password pairs belonging to UK higher education and research personnel circulating on the dark web in the year to June 2026, with compromised identities rising from roughly 10,000 to 15,000 year on year and more than 61 million queries to malicious sites blocked. Jisc's David Batho expects threat actors with hacking-as-a-service and AI tooling to increase attacks on UK education and research. That is the credential supply that makes portal-level intrusions cheap.
Separately, and importantly, a different institution has been hit hard this summer. The University of Nottingham, not Nottingham Trent, was listed by ShinyHunters on 9 June 2026. BushidoToken's UK Cybercrime Journal reports over 40GB of billing, student finance, and campus portal data leaked from Nottingham and its Malaysia and China campuses, with Have I Been Pwned analysis finding over 455,000 unique email addresses alongside ethnicities, disabilities, and passport numbers. TheNextWeb, citing TechCrunch and Mandiant, ties that campaign to CVE-2026-35273, an unauthenticated remote code execution zero-day in Oracle PeopleSoft PeopleTools 8.61 and 8.62 rated CVSS 9.8, exploited across roughly 300 servers at more than 100 organisations, about two thirds of them universities and colleges, with no patch available at the time of Oracle's advisory. A ShinyHunters member told TechCrunch the group took "hundreds of thousands of student records."
Two similarly named Nottingham institutions, two different actors, two different intrusion methods. No source connects ShadowByt3$ to ShinyHunters, to CVE-2026-35273, or to PeopleSoft, and this brief does not either. A third listing adds further noise: RecentBreaches reports that the group "thegentlemen" listed NTU Alumni Club on 10 August 2026 with no data types itemised and no affected-individual count, an unconfirmed claim against an entity whose relationship to either university is not established in the sources. Anyone triaging "NTU breach" alerts this month is looking at at least three distinct claims that automated feeds will happily blur together.
The strategic read: student-facing web applications are now a preferred initial access surface for education-sector extortion, and the data sitting behind admissions portals, unencrypted identity documents, immigration status, family addresses, is materially more dangerous than the credential dumps that dominated earlier years.
The Attack Technique
The only technical detail asserted anywhere is the entry point. Ransomware.live's reproduction of the actor's post and Hendry Adrian both name webapps.ntu.ac.uk as the access vector. Undercode News describes it more loosely as "web application access" and "web applications associated with Nottingham Trent University."
Beyond the hostname, there is nothing. No CVE, no exploit chain, no credential-stuffing claim, no malware family, no persistence mechanism, no dwell-time estimate, and no confirmed ransomware deployment. The extortion is data-theft-driven; nothing in the sources establishes encryption of university systems, and the "locked out" language in the listings refers to the university revoking the attacker's access rather than the attacker denying the university theirs.
The document-level detail in the listing, named PDF filenames such as Degree Transcript.pdf and CV.pdf, passport scans, and per-field references to specific portal screens, is consistent with an authenticated or authorisation-bypassed session against an applicant portal with direct object access to uploaded files. That is an inference from the actor's own description, not a finding. The realistic candidate paths worth hunting for are IDOR or broken access control on document retrieval endpoints, an exposed admin or staff view, or valid credentials sourced from the infostealer market Jisc describes. Defenders should not assume PeopleSoft involvement here purely because of the concurrent ShinyHunters campaign against the neighbouring institution.
What Organizations Should Do
-
Inventory and expose-check every
webapps-class subdomain. Enumerate student, applicant, alumni, and staff-facing web applications sitting outside the main estate, confirm each has an owner, and pull authentication and file-download logs for the 15 to 26 August window. Portals built for admissions cycles are frequently outside standard patch and monitoring scope. -
Audit document retrieval for broken access control. Any endpoint serving uploaded passports, transcripts, or CVs should be tested for IDOR, sequential or guessable identifiers, and missing per-object authorisation. Where a single authenticated session can enumerate other applicants' files, that is the whole incident.
-
Patch or mitigate Oracle PeopleSoft as an independent priority. CVE-2026-35273 affects PeopleTools 8.61 and 8.62, scores CVSS 9.8, and was unauthenticated and unpatched at disclosure per TheNextWeb's reporting. Apply Oracle's current guidance, restrict internet exposure of PeopleSoft interfaces, and hunt for MeshCentral agents and anomalous SSH activity, which BushidoToken documents as ShinyHunters tradecraft on this campaign.
-
Stop storing identity documents in plaintext by default. Passport and visa PDFs should be encrypted at rest with separate key management, purged on a hard retention schedule once the admissions decision is made, and served only through short-lived, access-logged, per-request tokens.
-
Treat credential hygiene as a supply-chain problem. Given Jisc's finding of 144,000-plus compromised higher education credential pairs in a single year, enforce phishing-resistant MFA on all web application entry points, monitor infostealer dumps for institutional domains, and force resets on any match rather than waiting for abuse.
-
Prepare the notification decision now, not after leak-site publication. If passport numbers and dates of birth are in scope, UK institutions face ICO reporting obligations and a high risk to data subjects. Pre-draft the notification, brief the fraud and immigration-support teams, and warn affected international applicants specifically about visa-themed and tuition-payment-themed social engineering built from their own transcripts and CVs.
-
Deconflict your own alerting. Set explicit tracking on "Nottingham Trent University," "University of Nottingham," and "NTU Alumni Club" as three separate entities with three separate claimed actors. Conflating them will corrupt your incident record and any downstream reporting you produce.
Wasteland will update this brief if Nottingham Trent University, the ICO, or the NCSC issues a statement, or if ShadowByt3$ publishes the claimed data.
Sources: Ransom! Knottingham Trent University (AUG-2026) | ShadowByt3$ Allegedly Breaches Nottingham Trent University, Steals... | Over 144,000 stolen university usernames have been discovered on th... | ShinyHunters breached 100+ companies through an unpatched Oracle Pe... | UK Cybercrime Journal: University of Nottingham Breached by ShinyHu... | NTU Alumni Club Ransomware Claim (2026) — What’s Alleged & Am I Aff... | University of Nottingham Cyber-Attack: Students' Data Breached - Wh... | Ransomware.live - Victim: Knottingham Trent University