The University of Oxford disclosed a breach of its CareerConnect careers service after third-party provider Group GTI reported that attackers compromised the platform on May 28 by exploiting an unspecified vulnerability. The incident exposed users’ first and last names, email addresses, and encrypted passwords for accounts that did not use single sign-on, prompting password resets for affected locally managed accounts. Oxford said the compromise was confined to GTI’s system and that there is no evidence university systems were breached.
Oxford said there is no evidence that course information, uploaded files, appointment details, or financial data were accessed, but warned students, staff, alumni, employers, research staff, and other users to watch for phishing and scam emails. GTI assessed the intrusion as likely aimed at credential collection, and the disclosure raised wider concern because the compromised TargetConnect technology is used by other universities in the UK and overseas. The breach is Oxford’s second third-party exposure reported this year, following the separate Canvas incident tied to the ShinyHunters extortion gang.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Oxford disclosed the CareerConnect breach after Group GTI reported the compromise, stating the incident was limited to GTI's third-party system and not Oxford's own systems. The university invalidated affected locally managed passwords and warned users to watch for phishing and scam emails.
Oxford said attackers compromised the CareerConnect careers service platform operated by Group GTI on May 28. The breach exposed users' names, email addresses, and encrypted passwords for accounts not using single sign-on.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.