Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Debian Tomcat11 Moderate DDoS Authentication Bypass Vulnern DSA-6329-1

    June 8, 2026

    A Farmer Donated Land to Turn into a Park. The City Is Building a Massive Data Center Instead

    June 8, 2026

    SSA-064222 V1.0: Multiple File Parsing Vulnerabilities in Simcenter Femap before V2406

    June 8, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Oxford University discloses data breach after careers platform hack
    News

    Oxford University discloses data breach after careers platform hack

    adminBy adminJune 8, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oxford

    The University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised.

    This platform is also used by other UK educational organizations, such as King’s College London and the University of Manchester, to run their institution-specific career hubs.

    Founded in 1096, Oxford is a collegiate research university comprising 43 autonomous colleges with more than 26,000 students and over 5,900 research, teaching and research support staff, and is the oldest university in the English-speaking world.

    image

    Oxford University said the CareerConnect platform was breached on May 28 by attackers who gained access to users’ first names, last names, email addresses, and encrypted passwords (for users who do not sign in using Single Sign-On (SSO).

    “Alumni, research staff and employer users access CareerConnect with a password set locally on CareerConnect. These passwords were invalidated by GTI and users will be asked to reset their password next time they sign in,” the university said.

    “There is no evidence that course information, uploaded files, appointment information, or financial information were involved in this incident. GTI has stated this breach appeared to be focused on gathering credentials which may lead to phishing attempts.”

    The institution noted that the incident affected only GTI’s third-party system and that there is no evidence that the attack has compromised university systems. Additionally, GTI and the university have found no evidence that students’ passwords or financial information have been accessed.

    It also warned staff, students, and external CareerConnect users that they might be targeted by phishing or scam emails.

    This is the second data breach disclosed by Oxford University this year, following the ShinyHunters extortion gang’s breach of Instructure’s Canvas learning management system (LMS), which the university uses, in early May.

    After the attack, the hackers claimed to have stolen 280 million records tied to students and staff from 8,809 colleges, school districts, and online education platforms worldwide. Instructure reached an agreement with the cybercrime group, saying that the hackers returned the stolen data and provided shred logs confirming its destruction.

    Oxford University confirmed it was one of the victims, adding that its systems were not compromised and that the exposed data was limited to usernames, Canvas email addresses, messages exchanged between users on the platform, course names, and course enrolment information.

    An Oxford University spokesperson was not immediately available when contacted by BleepingComputer earlier today for comment on the CareerConnect data breach.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCVE-2026-11503 | THREATINT
    Next Article CVE-2026-11510 | THREATINT
    admin
    • Website

    Related Posts

    News

    A Farmer Donated Land to Turn into a Park. The City Is Building a Massive Data Center Instead

    June 8, 2026
    News

    Over 20,000 Instagram accounts stolen in Meta AI support hack

    June 8, 2026
    News

    Hands on with Intelligent Terminal, an AI-powered Windows Terminal

    June 7, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202630 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202630 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Our Picks

    Debian Tomcat11 Moderate DDoS Authentication Bypass Vulnern DSA-6329-1

    June 8, 2026

    A Farmer Donated Land to Turn into a Park. The City Is Building a Massive Data Center Instead

    June 8, 2026

    SSA-064222 V1.0: Multiple File Parsing Vulnerabilities in Simcenter Femap before V2406

    June 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.