糖心原创

Cyber attack incident

Text updated on Wednesday 22 July 2026.

The 糖心原创 has been the victim of a cyber incident and a significant amount of data in our student record system has been accessed by an external third party.

On Tuesday 9 June we identified unauthorised activity within our Campus Solutions student records platform. We immediately took the affected systems offline to contain the incident and launched a comprehensive investigation. 

While we are still investigating the nature of the incident, it is likely that data has been accessed by a well-known cybercriminal group that also targeted a number of other organisations.

We are working with the third party that maintains the Campus Solutions platform and with teams from JISC (Joint Information Systems Committee) to lead a forensic investigation into this incident.

We are in the process of verifying the exact scope of the data accessed and will provide further updates as our investigation confirms these details. 

What we are doing

  • Containment: The affected system was immediately secured and isolated.
  • Forensics: We are working with expert cyber analysts to identify the root cause.
  • Regulatory compliance: We have formally reported this incident to the Information Commissioner’s Office, Action Fraud, and to the Office for Students. 
  • Support: We have set up a phone line if you have any further questions and we will provide any further updates as soon as we can. 
  • Credit monitoring: We are offering a free credit-monitoring service to students.

Recommended actions for students, alumni and applicants

While we continue our work, we urge you to take the following precautions:

  • Monitor your accounts: Be vigilant regarding any unexpected or suspicious communication – especially those requesting financial information or credentials  
  • Update credentials: As a proactive measurement, update passwords for any accounts that share credentials with any university systems you use 
  • Stay informed: We have established a dedicated support line at 0115 74 86500, which we will update in real-time as we learn more; please also keep checking your university email address for further updates. The helpline is available from 10am-4pm, Monday to Friday.

This is a serious incident, and we are very sorry if your information has been involved. If you have any questions or concerns, please do contact our support helpline on 0115 74 86500. The helpline is available from 10am-4pm, Monday to Friday.

FAQs

What happened?

The university identified unauthorised activity within its Campus Solutions student records platform on 9 June 2026 and took the affected systems offline immediately to contain the incident.

We have been working with specialist cyber security and forensic advisers to investigate the nature and extent of the incident. The investigation has established that data within the student records system was accessed by the external third party and we are continuing to verify the scope of the information affected and the extent of any access to that information.

We have reported the incident to the Information Commissioner's Office, Action Fraud and the Office for Students and continue to engage with relevant authorities. We recognise that our community want clear information about what has happened and we are committed to being as transparent as possible. We will continue to update this page as further findings are confirmed through the ongoing investigation.

 
How did this happen?
Our forensic investigation has identified that an external threat actor exploited a vulnerability in Oracle WebLogic, which supports our Campus Solutions platform. This vulnerability allowed unauthorised remote code execution, giving the attacker access to parts of the system. Our investigation into the full attack timeline is ongoing. We have since contained the incident and the system is currently offline while we secure and rebuild our system. Our understanding is that the university also didn’t receive any direct request for a financial ransom for this data.    
 
Has this been reported to the relevant authorities?
Yes. We have notified the Information Commissioners’ Office (ICO) in accordance with our legal obligations. The National Cyber Security Centre (NCSC), the Office for Students (OfS), UCAS and Action Fraud has been notified.
 
What data has been accessed in this incident?

We are operating on the precautionary assumption that students and some alumni and applicant personal data has been accessed, and we have been contacting those who may be affected to suggest protective measures.  We sincerely apologise for this situation. 

Our forensic investigation is still ongoing and we do not yet have a confirmed list of every data field that has been accessed. However, to ensure you can take appropriate protective steps, we are being transparent about the data we believe may have been accessed based on what is held in the system. 

The following categories of data may have been accessed. Not all of this will apply to every individual, and some of this data may not have been taken – but we want students, applicants and alumni to be aware of the worst-case scenario, so they can act accordingly: 

  • Contact information (names, email, phone number and postal addresses) 
  • University-related details (course information, student/staff ID, UCAS ID) 
  • Financial information (fee payment records - bank details, payer email, transaction amounts, bursary information, debt information, financial aid, visa information). Please note: this is unlikely to be information we hold for applicants. 
  • Personal information (date of birth, gender, nationality, photograph, NI numbers, protected characteristics - sexual orientation, religion, disability/health).

While we are committed to providing information as soon as possible, some aspects of the incident are still being investigated and verified. As part of that process, the university is continuing to assess:

  • the full scope of the information that was affected;
  • the nature and extent of any access to that information;
  • which individuals may have been affected; and
  • whether any further communications or notifications may be required.

We recognise that this may be frustrating, however, it is important that the information we provide is accurate and based on verified findings rather than speculation. For that reason, there may be some questions that we are not yet able to answer in full.  As further information is confirmed, this page will continue to be updated. Where appropriate, the university will also communicate directly with affected individuals in accordance with legal and regulatory obligations.

 
Does this affect other systems such as OneDrive, email or other Systems?
No. This incident relates specifically to Campus Solutions (PeopleSoft), our student records system, which operates within an isolated IT environment maintained by an independent third-party provider. Microsoft 365 services including OneDrive, email, Teams and Moodle were not affected.
 
Will you be offering any fraud- or credit-monitoring services?

We have arranged a 12-month subscription to TransUnion’s TrueIdentity, an online credit and identity monitoring service. This service includes: unlimited online access to the TransUnion Credit report, which can help determine credit-related identity theft or fraud; credit monitoring alerts and dark web monitoring; as well as resources on how to keep your data safe. 

Students and alumni can sign up to this service by calling our helpline on 0115 74 86500 from 10am-4pm, Monday to Friday.

Our investigation is ongoing and we will not be able to offer this service to applicants until we have a clearer picture of whose data has been impacted.

 
What should I do to protect myself?

While we work to secure our system, we recommend that you take these steps to keep your personal information safe:

  • Change Your Passwords: If you use the same password for your university account that you use for other personal accounts (like email, banking, or social media), please change those passwords immediately. Use a unique, strong password for each of your important accounts.
  • Be Alert for Phishing: Criminals may use your compromised contact details to send fraudulent emails, texts, or social media messages. These messages often appear to come from official sources—like the University, your bank, or government agencies—and may ask you to "verify" your details or click a link.  Always be sceptical of unexpected requests for information.
  • Don't Click, Don't Reply: Do not click on links, download attachments, or reply to suspicious messages. If you receive a communication that seems unusual, contact the organisation directly using a verified phone number or website (do not use the contact details provided in the suspicious message). 
  • Enable Multi-Factor Authentication: Wherever possible, turn on "Two-Step Verification" or "Multi-Factor Authentication" on your personal accounts. This adds an extra layer of security that prevents someone from accessing your account even if they have your password.  
  • Monitor Your Accounts: Keep a close eye on your bank statements and any online accounts for unauthorised activity.  
 
How do I spot a phishing email?

Phishing emails can take many forms and can often be very sophisticated and convincing. Below are a few things to look out for that may indicate that an email is not what it seems:

  • Unsolicited emails asking you to click a link and log in
  • Messages that seem too good to be true
  • Email addresses that don’t match the organisation they claim to be from
  • Generic greetings such as 'First_Name Last_Name has shared a file with you'
  • Unexpected attachments
  • A sense of urgency (e.g. threats your account may be closed)
  • Links that look similar to genuine websites but contain small differences
  • Requests for personal information (e.g. username, password or student loan details)
  • Emails where the content appears as an image rather than normal text

Remember that we will never ask you to provide your password via email. Please treat any requests to provide personal information such as a password with suspicion.

More information can be found on Current Students.

 
What should I do if I expect an email to be a phishing attempt?

If you suspect an email to be a phishing attempt, do not click any links contained within and do not provide any information it may be asking for. You should permanently delete the email.

If you have received an email to your university account that you suspect of being a phishing email, instead of deleting it, please report it using the Report Phishing button in Outlook.

  • Outlook desktop app: Click Report Message → Phishing
  • Outlook mobile app: Tap the three dots (…) → Report Message → Phishing
  • Outlook web version: Click Report → Report phishing

Once reported, the email will be moved to your Deleted Items folder.

 

糖心原创

University Park
Nottingham, NG7 2RD

telephone: +44 (0) 115 951 5151
fax: +44 (0) 115 951 3666
email: Contact us