Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

nottingham.ac.uk

nottingham.ac.uk

Discovered 2026-06-09 19:26 UTC
Est. attack date 2026-06-09
Country GB

Description:

Over 40 GB of billing and payment records, credit card and payment details, student finance data, and campus portal exports from the University of Nottingham and its Malaysia and China campuses was compromised, including payer contact information, transaction amounts, IP addresses, full names, home addresses, postcodes, email addresses, phone numbers, dates of birth, and other internal campus data. | Size: 19GB+ (compressed) | Updated: 10 June 2026 | SHA256: d3aaaf06dd857deec3866072cc2876780623d880992e8d735094db4779535873

Infostealer activity detected by HudsonRock

Compromised Employees: 338

Compromised Users: 5611

Third Party Employee Credentials: 637


External Attack Surface: 178


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • nottingham-ac-uk.mail.protection.outlook.com. Microsoft 365
TXT Records
  • MS=ms57537667
  • atlassian-domain-verification=3JE9cke8XsM59Oh0tT73QNEhs6Gw2bfMaxiyc9quAuZdW4al9BGIrCVs9s4rfgQy
  • adobe-idp-site-verification=7f2ebc573bc1769a828f63ec966bd01a1cd05ccf9cc64fb55d97874f5a23589e
  • google-site-verification=sa8GOryPIpBt5npSI7xAqPehUyiGET3xk-LEZ1GbOig
  • apple-domain-verification=xbJn3kEmmhW9Ou4k
  • QuoVadis=cd924184-d16f-4388-a06f-60841f6bfc43
  • SERIALUP
  • 202503061523064202abtmsdafw16qhs6h09zgmyk0aejrl45afb38dgzeh5qse9
  • 1Q6+0cep9R4exJx3RGfB8ObBpeO/kDtYsZYD8jmj1cupaJIDz8KUExk/Qsl2dqgt95g0lyRDLCa6102bJk+lFA==
  • access-domain-verification=5c30dffba43dd9ca58fedebac54fb7913da919b1a1de9d7ab834311f7d5b1abf
  • brevo-code:b1414e0a234265a2faa294058248ae06
  • ddosx-site-verification=1d20e59f864521a97440915cea9da380eb5a6f183a9d98ad6bc2078c5575be8a
  • jamf-site-verification=qEzRIpanfBewOTlcO6f1bA
  • anthropic-domain-verification-p4z2z4=x2uFL7ZXVblci85yjXadTfaR2
  • google-site-verification=L5AVOihugr8sVP2OrvjUPTQBk8cBP9w_FPp82WCtl_E
  • smartsheet-site-validation=UsjFeY2ICM88UrzI9ciqacTLcpeAJRkR
  • MS=ms55552287
  • CD7F2D11-A9B7-4E5E-BF97-117FD5A2B475
  • v=spf1 exists:%{i}._spf.nottingham.ac.uk include:_spf.nottinghamacuk.vueliopm.com include:mail-eu.geckoform.com ip4:128.243.220.65 ip4:128.243.44.55 " "ip4:51.4.80.0/27 ip4:194.73.8.7/32 ip4:40.107.0.0/16 ip4:52.100.0.0/14 ip4:104.47.0.0/17 ip4:199.19.0.0/21 ip4:162.88.4.0/23 include:amazonses.com include:spf.zoho.eu include:_spf0000000.nottingham.ac.uk include:spf.protection.outlook.com ~all
  • 25E3Z31XTF6U404A703LSJS4SGE9OCQU1D4OAYZH6
  • adobe-idp-site-verification=def3d1d831162020848a32206541217c00bc2dfbc6199ce745dbbca7033628ef
  • taegis-domain-verification=a38968c7875c6fa3ab0176302a193949922e1ac9fe1b748289cebff722874688
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Microsoft 365 Anthropic JamF