On August 19, 2026, threat actor ShadowByt3$ compromised Knottingham Trent University (GB) after gaining access via webapps.ntu.ac.uk and allegedly stole high-risk personal data, including passport details, dates of birth, contact information, home addresses, and academic/employment records. The victim was reportedly locked out, and the attacker threatened to leak the data if the university did not comply, impacting the United Kingdom. #UnitedKingdom
Incident Details
- Victim: Knottingham Trent University
- Sector: Education
- Country: GB
- Actor: ShadowByt3$
- Source: https://transfer.it/t/dqbRpEkBmbxB
- Discovered: 2026-08-25T14:24:56.130872+00:00
- Published: 2026-08-25T14:24:40.137789+00:00
Information
- Breached on August 19, 2026 through webapps.ntu.ac.uk.
- Access was obtained to the university portal and data was taken before access was locked.
- Passport numbers and passport document details were exposed through raw PDF copies.
- Dates of birth were visible on the main data profile screen.
- Nationalities and countries of birth were confirmed through passport logs and registration metadata.
- Full legal names were exposed.
- Personal email addresses were revealed through the portal login view.
- Mobile phone numbers were collected from the dashboard contact view.
- Permanent and correspondence home addresses were exposed, including full street-level details and postal codes.
- Complete academic history was taken from transcript and grade completion files.
- Employment and professional history was taken from the CV file.
- Professional reference names were exposed through letters of recommendation.
- Threats were made to leak the data and damage the organizationβs reputation if demands were not met.

Disclaimer: This post is based on public claims made by the ransomware group "ShadowByt3$". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.