[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f18Lg8HOP4w9kwxPnaDEdNKiGIdULQlCM8FlBqdOg3mc":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":23,"source":24,"isVerified":4,"isSpamList":25,"isSensitive":4,"severity":26,"processingStatus":27,"logoUrl":28,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66a0dd491e604458580cee","OxfordCareerConnect2026","University of Oxford CareerConnect 2026 Data Breach","university-of-oxford-careerconnect-2026","ox.ac.uk",{"name":12,"sector":13,"country":14,"website":10},"University of Oxford","Education","United Kingdom","2026-05-28T00:00:00.000Z","2026-07-27T00:05:49.652Z",0,[19,20,21,22],"First names","Last names","Email addresses","Encrypted passwords for non-SSO accounts","\u003Cp>\u003Cstrong>The University of Oxford CareerConnect 2026 data breach\u003C\u002Fstrong> is an incident in which the university confirmed unauthorized access to user account data on its third-party careers platform. Platform provider GTI informed Oxford on May 28, 2026 that an unauthorized party had been able to access first names, last names, email addresses, and encrypted passwords for accounts that did not use Single Sign-On.\u003C\u002Fp>\n\u003Cp>The Oxford University Careers Service notice is the primary source, while BleepingComputer independently reported the university's statement, user groups, and limited scope. Oxford and GTI did not publish a unique affected-user count. LeakData therefore keeps pwnCount at zero to mean that a reliable total is unknown, not that nobody was affected.\u003C\u002Fp>\n\u003Ch2>Confirmed Scope of the Incident\u003C\u002Fh2>\n\u003Cp>According to Oxford, CareerConnect is a third-party system provided by GTI and was accessed without authorization on May 28. Attackers could reach platform users' first names, last names, and email addresses. Encrypted password values were also within reach for people who signed in with a password stored locally in CareerConnect.\u003C\u002Fp>\n\u003Cp>GTI confirmed that the security vulnerability had been fixed and additional safeguards were put in place. The university continued assessing the impact with the provider and said it would contact affected users directly if further action became necessary. The notice did not identify the attacker, exploited flaw, duration of access, or volume of downloaded data.\u003C\u002Fp>\n\u003Ch2>Student Accounts and SSO\u003C\u002Fh2>\n\u003Cp>Oxford students sign in to CareerConnect through the university's Single Sign-On system. The university therefore said student passwords were not affected and that the accessible fields for student accounts were limited to names and email addresses. This distinction means the encrypted-password class does not apply to every user in the incident.\u003C\u002Fp>\n\u003Cp>SSO means no local student password was stored in the CareerConnect database, but it does not eliminate the confirmed access to names and email addresses. The record lists data classes for the incident as a whole while preserving the user-group limit in this description. It should not be read as theft of student passwords or Oxford SSO credentials.\u003C\u002Fp>\n\u003Ch2>Alumni, Research Staff, and Employers\u003C\u002Fh2>\n\u003Cp>Alumni, research staff, and employer users signed in with passwords set locally in CareerConnect. Oxford said encrypted password values for these accounts fell within the accessible scope. GTI invalidated the local passwords, and users were required to create a new password the next time they signed in.\u003C\u002Fp>\n\u003Cp>An encrypted password is not the same as a plaintext password, but it can create risk through offline cracking and credential reuse on other services. The university said the incident appeared focused on gathering credentials that might support phishing. No evidence was disclosed showing that passwords had been decrypted and successfully used.\u003C\u002Fp>\n\u003Ch2>Data Reported as Unaffected\u003C\u002Fh2>\n\u003Cp>Oxford and GTI said there was no evidence that course information, uploaded files, appointment information, or financial information was involved. There was also no evidence that the university's own systems had been compromised; the event related only to the third-party CareerConnect environment. These exclusions explain the narrow dataClasses entry.\u003C\u002Fp>\n\u003Cp>Career applications, resumes, interview notes, payment data, and internal university files are not added as confirmed scope. “No evidence” is the published investigative finding rather than a claim of absolute technical impossibility. The record can be updated if new official evidence changes the scope; the current version includes only verified fields.\u003C\u002Fp>\n\u003Ch2>Phishing Risk and Response\u003C\u002Fh2>\n\u003Cp>GTI said the incident appeared aimed at collecting credentials, and Oxford warned staff, students, and external CareerConnect users about suspicious emails and messages. Users were advised to verify requests for personal or financial information through an independent channel and report suspicious communications to the university's information-security team.\u003C\u002Fp>\n\u003Cp>Invalidating local passwords, fixing the vulnerability, and deploying additional controls were direct response measures. Oxford said the platform was secured and safe to use again while it continued assessing the impact with GTI. The university also confirmed that it had no information indicating ransomware, a claim of responsibility, or an attacker attribution.\u003C\u002Fp>\n\u003Ch2>Do Not Merge With Other Oxford Incidents\u003C\u002Fh2>\n\u003Cp>This record covers only the May 28, 2026 incident involving the third-party CareerConnect platform. Oxford was also affected that year by a different incident at the Instructure Canvas learning platform it used. The Canvas event involved another provider, date, system, and set of data classes; the two events must not be merged into one breach or person count.\u003C\u002Fp>\n\u003Cp>The verified conclusion is that CareerConnect first names, last names, and email addresses were accessed, along with encrypted passwords for non-SSO alumni, research-staff, and employer accounts. There was no evidence of impact to student passwords, financial data, course information, uploaded files, appointments, or Oxford's own systems, and no unique affected-user total was disclosed.\u003C\u002Fp>","Third-party CareerConnect unauthorized access",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fox_ac_uk.svg"]