Key developments
University of Nottingham breach exposes 454,600 students
Safestate reported that the University of Nottingham confirmed attackers accessed its student records system, exposing personal and financial data for 454,600 current and former students. ShinyHunters claimed responsibility, said it exfiltrated more than 40 GB, and posted sample files; exposed records reportedly include names, addresses, phone numbers, dates of birth, passport numbers, and billing or payment details across UK, Malaysia and China campuses. The university said it notified the UK Information Commissioner's Office and Action Fraud and is working with the third-party vendor that maintains the platform.
Why it matters
The breach combines identity and financial data at very large scale, creating immediate fraud and phishing risk for students and alumni.
Sources & driving stories
SAFESTATE
Safestate coverageSpanish cannabis-club app exposed 985,000 IDs
The Verge reported that security researcher Sammy Azdoufal found passports, driver's licenses and selfies exposed at public URLs with no authentication in Cannabis Club Systems/Nefos Solutions' PuffPal setup used by clubs in Spain. Azdoufal estimated at least 985,000 photo IDs were exposed and said the records could also include phone numbers, addresses, cannabis preferences and consumption history; he also found a plain-text Stripe key, a profile-access flaw, weak passwords and exposed private chat messages. Nefos said it is shutting down PuffPal and the vulnerable APIs, coordinating with Ireland's Data Protection Commission, and notifying potentially affected users.
Why it matters
It shows how a consumer verification app can expose government IDs at scale and trigger cross-border privacy regulator scrutiny.
Sources & driving stories
THE VERGE
The Verge coverageCoupang hit with record $409 million fine
MLex reported that South Korea's Personal Information Protection Commission finalized a 624.7 billion won, or about $409 million, penalty against Coupang after a November 2025 breach. Regulators concluded the company lacked adequate systems to protect and manage customer information and also found unlawful collection of online activity records across third-party websites and mobile apps. The action is one of the largest privacy penalties in Asia and follows earlier remediation steps reported by the company.
Why it matters
The case signals that regulators are treating breach controls and tracking practices as linked privacy violations worthy of record-level penalties.
Sources & driving stories
MLEX · Jenny Lee
MLex coverageWorth noting
WORTH NOTING
VRChat breach notice disputed
A notice claimed data for more than 2.4 million users was involved, but VRChat says it never submitted the filing and has no reason to believe its systems were compromised.
WORTH NOTING
Massachusetts privacy bill passes House
The bill would expand access, correction, deletion and opt-out rights, ban precise geolocation sales, and add stronger protections for minors, so the Senate's next move will decide whether it becomes law.
Still unclear
OPEN QUESTION
How many other PeopleSoft deployments are exposed?
Nottingham appears to be part of a wider ShinyHunters campaign, so the same exploit path may affect many more institutions.
OPEN QUESTION
Will Massachusetts keep the private right of action?
That enforcement clause may determine whether the new privacy framework has real teeth or is mostly symbolic.
