Ransom! Knottingham Trent University (AUG-2026)

Ransom! Knottingham Trent University (AUG-2026)
On August 19, 2026, threat actor ShadowByt3$ compromised Knottingham Trent University (GB) after gaining access via webapps.ntu.ac.uk and allegedly stole high-risk personal data, including passport details, dates of birth, contact information, home addresses, and academic/employment records. The victim was reportedly locked out, and the attacker threatened to leak the data if the university did not comply, impacting the United Kingdom. #UnitedKingdom

Incident Details

  • Victim: Knottingham Trent University
  • Sector: Education
  • Country: GB
  • Actor: ShadowByt3$
  • Source: https://transfer.it/t/dqbRpEkBmbxB
  • Discovered: 2026-08-25T14:24:56.130872+00:00
  • Published: 2026-08-25T14:24:40.137789+00:00

Information

  • Breached on August 19, 2026 through webapps.ntu.ac.uk.
  • Access was obtained to the university portal and data was taken before access was locked.
  • Passport numbers and passport document details were exposed through raw PDF copies.
  • Dates of birth were visible on the main data profile screen.
  • Nationalities and countries of birth were confirmed through passport logs and registration metadata.
  • Full legal names were exposed.
  • Personal email addresses were revealed through the portal login view.
  • Mobile phone numbers were collected from the dashboard contact view.
  • Permanent and correspondence home addresses were exposed, including full street-level details and postal codes.
  • Complete academic history was taken from transcript and grade completion files.
  • Employment and professional history was taken from the CV file.
  • Professional reference names were exposed through letters of recommendation.
  • Threats were made to leak the data and damage the organization’s reputation if demands were not met.

Disclaimer: This post is based on public claims made by the ransomware group "ShadowByt3$". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live