NEWS
Oxford CareerConnect Leak Sits on a Shared Campus Platform
Oxford confirmed a May 2026 CareerConnect leak of names and emails. The quieter fact is TargetConnect already powers more than 110 career services.
Group GTI told the University of Oxford on 28 May 2026 that attackers had reached CareerConnect, exposing names and email addresses. Alumni, research staff, and recruiters who used a local password also had those encrypted secrets taken. Students on Oxford single sign-on did not.
The careers portal is a GTI product the firm sells as TargetConnect, and GTI’s own site now puts it in front of more than 110 career services. Oxford published a notice. Almost nobody else on that list did.
GTI Told Oxford, Then Went Quiet
On Thursday 28 May, GTI, the London, Wallingford, and Dublin firm behind CareerConnect, informed Oxford that an unauthorised party had reached the platform. The Careers Service notice, dated 1 June, said the attackers obtained first names, last names, and email addresses, plus encrypted passwords for anyone who did not sign in with single sign-on.
A University spokesperson said Oxford first learned it was “impacted on Thursday afternoon” of that week. Students received an email late on Friday 29 May. That message said student names and email addresses were involved and that “user passwords and any other personal data were not obtained,” a line written for the SSO majority. The fuller 1 June notice drew a harder line for alumni, research staff, and employer accounts.
GTI said the flaw had been fixed and extra controls put in. It did not publish its own incident note, did not give a headcount, and did not say which other campuses sat on the same build. Oxford said it was still waiting on precise numbers from the vendor.
THE MAY CLOCK ON CAREERCONNECT
- 28 May 2026: GTI tells Oxford the careers platform was reached without permission.
- 29 May 2026: Oxford emails students, says the portal is secured, and asks them to treat odd mail with care.
- 1 June 2026: The Careers Service posts the public notice and confirms local passwords were invalidated.
Oxford stressed that the break-in lived on a third-party system. It said there was no sign of a hit on University machines, and no sign that course records, uploaded files, appointment logs, or money data were in the take.
The Password Split on CareerConnect
The damage was not even. Current students reach CareerConnect through Oxford SSO, so the portal does not keep a separate student password. The notice said only their names and emails would have been taken. Alumni, research staff, and employer users set a password on CareerConnect itself. Those hashes were in reach, and GTI killed them. The next login forces a reset.
WHO LOST WHAT ON CAREERCONNECT
| User group | How they sign in | Taken in the incident | What GTI did |
|---|---|---|---|
| Current students | Oxford SSO | Names and emails | No local password to reset |
| Alumni | Local CareerConnect password | Names, emails, encrypted passwords | Password killed; reset on next login |
| Research staff | Local CareerConnect password | Names, emails, encrypted passwords | Password killed; reset on next login |
| Employer users | Local CareerConnect password | Names, emails, encrypted passwords | Password killed; reset on next login |
That split is why a student inbox could read as a near miss while a recruiter or graduate from ten years ago had to pick a new secret. Encrypted is not the same as public, but a hash is still a thing a patient attacker can work on, which is why GTI did not leave those logins live.
The University told students there was no immediate action for them beyond watching for odd mail, and that it had seen no sign the stolen contact data had been used or shared as of early June. It also said it was “expecting more information from the external provider GTI on precise numbers.” That figure never arrived in public.
More Than 110 Career Services Share One Platform
Oxford is the campus that wrote the letter. The product underneath is not Oxford’s. GTI markets TargetConnect as a student-first platform for university careers teams, a single place for jobs, appointments, events, and employer contact. The company’s homepage says employers already reach students through more than 110 career services. It lists a team of 155-plus people across 31 nationalities, with offices in London, Wallingford, and Dublin and staff in Germany, Australia, and the United States.
On GTI’s own educator pages, universities talk about the same stack by name. That is not a victim list. It is a map of who already poured student and recruiter records into one vendor.
CAMPUSES GTI PUTS ON TARGETCONNECT
- Oxford: CareerConnect at oxford.targetconnect.net, for students, researchers, alumni, and recruiters.
- University of Wolverhampton: replaced Career SPACE on 26 January 2026 and told students to use university SSO.
- University of London, Leeds, and Cardiff: named as users in GTI student quotes on the educator site.
- Deakin, West London, and De Montfort: careers teams quoted on the same GTI page after rollout.
- King’s College London and Manchester: widely named as CareerConnect hosts; neither issued a public incident note.
If the hole sat in shared code, the blast radius is the customer list. If it sat in an Oxford-only setup, the other campuses still owe their own students a yes or a no. GTI did not draw that line. King’s and Manchester did not either. Searches through September 2026 still find Oxford as the only university that described this incident in public.
That quiet is the part that does not match the Canvas circus from the same month. A careers CRM is a dull system until someone uses it to send a fake internship offer. Then it is a directory of people who are already looking for a job.
ShinyHunters Got Paid After the Canvas Raid
CareerConnect was the second outside platform to fail Oxford in May. Earlier that month Instructure’s Canvas learning system, used by Oxford and thousands of other schools, was hit by the group known as ShinyHunters. The gang timed the pressure for exam season. Students lost learning materials, tests, and grades while the vendor fought the incident.
The claimed haul was vast: usernames, email addresses, course names, enrolment records, and messages for up to 275 million students, teachers, and staff across circa 8,800 institutions. Instructure “reached an agreement” with the gang, then said it had “received digital confirmation of data destruction (shred logs)” and had “been informed that no Instructure customers will be extorted as a result of this incident, publicly or otherwise.”
Oxford told students the Canvas event was separate, and that some Oxford Canvas data was affected, which “may include names, email addresses… and messages exchanged between users within Canvas.” CareerConnect did not ride that extortion plot. It was a smaller, quieter grab, aimed at logins rather than a terabyte dump.
TWO MAY FAILURES, TWO VENDORS
| CareerConnect (GTI) | Canvas (Instructure) | |
|---|---|---|
| When Oxford learned | 28 May 2026 | Earlier in May 2026 |
| Who else sits on it | More than 110 career services; Oxford is the campus that published | Circa 8,800 schools and colleges |
| Taken | Names, emails; encrypted passwords for local logins | Usernames, emails, course names, enrolment, messages |
| Not taken, per the vendor or campus | Files, appointments, course records, money data, Oxford’s own systems | Instructure said course content, submissions, and credentials were not in the incident |
| End state | Patch, password kills, no public headcount | Agreement, shred logs, a promise of no further customer extortion |
Put together, they are two vendor data breaches in one term, both on systems Oxford does not host. Attackers did not need the University network. They needed the SaaS tools students already treat as campus infrastructure.
GTI Called It a Credential Harvest
GTI’s line, relayed by Oxford, was blunt about motive. The firm said the break-in “appeared to be focused on gathering credentials which may lead to phishing attempts.” Names plus university emails are enough to write a fake careers-fair reminder, a bogus internship shortlist, or a password-reset note that looks like CareerConnect. Alumni and recruiters, who live outside SSO, were the group that also lost a hash.
When the same institution is hit through multiple outside providers in the same year, it points to a broader problem: universities are relying on sprawling vendor ecosystems without applying enough continuous oversight to the systems that now hold student, alumni, and staff data.
Michael Centrella, Head of Public Policy, SecurityScorecard
Centrella added that attackers no longer need a university’s core network, and that names and emails from a careers tool help them write better lures because the platform is already used for internships, events, and recruiter traffic. That is the second-order harm: not a dump of transcripts, but a clean list of people who expect mail about jobs.
The public fight on this incident barely happened. Canvas produced threats, deadlines, and a deal. CareerConnect produced a Careers Service page and a Friday email. By July the trail on X was aggregator copy, not students comparing notes. A harvest that never hits a leak site is easier to file as minor. It is also easier to reuse in September, when internships open again.
A Headcount GTI Has Not Published
UK rules still sit on the controller, not the vendor’s press mood. The ICO tells organisations to report a notifiable breach within 72 hours of becoming aware of it, where feasible, and to tell people without undue delay if the risk to them is high. Oxford’s public file shows awareness on 28 May and a student email the next afternoon. It does not show the ICO filing, the number of alumni hashes, or whether GTI treated this as one campus or as a product incident.
WHAT WE KNOW
- The date: GTI informed Oxford on 28 May 2026 that CareerConnect had been reached.
- The take: Names and emails for users; encrypted passwords only where a local CareerConnect login existed.
- The patch: GTI said the flaw was fixed, extra measures were added, and local passwords were killed.
WHAT IS UNCONFIRMED
- The count: No public figure for Oxford accounts, let alone for other TargetConnect campuses.
- The radius: No other university has said it was, or was not, in the same window.
- The regulator file: No published ICO notice tying this incident to a closed case.
In September 2026 Oxford opened registrations for Michaelmas careers fairs on the same CareerConnect stack. The portal is back in the job-season loop. The headcount from May is still GTI’s secret.
Frequently Asked Questions
What Is the Difference Between CareerConnect and TargetConnect?
CareerConnect is Oxford’s branded front door. TargetConnect is GTI’s product name for the same class of careers CRM, and Oxford’s own help pages send users to oxford.targetconnect.net. GTI also runs targetjobs in the UK and gradireland in Ireland, which is how one vendor can sit under campus logins and public graduate job boards at the same time.
Does UK GDPR Give Students 72 Hours’ Notice?
No. The 72-hour clock is for a notifiable report to the ICO after the organisation becomes aware of a breach, where that report is required. Telling the people involved is a separate duty, triggered when the risk to their rights is high, and it runs “without undue delay” rather than on a 72-hour stopwatch. Oxford’s student email went out the day after GTI called.
Which Other GTI Brands Sit Beside the Careers Portal?
Beside TargetConnect, GTI sells targetjobs and gradireland as large student opportunity sites, plus Cibyl research that it says draws on 100,000 school leavers and undergraduates a year across 300 million data points. Those are separate products. They show how wide the firm’s student-data footprint already is even before you count campus CRM seats.
Can Oxford Alumni Still Use CareerConnect After the Reset?
Yes. Alumni keep lifetime access, but they sign in with a local CareerConnect password rather than Oxford SSO, which is why their hashes were in the incident and why GTI forced a reset. The alumni pages still point people to the same password-protected Careers site to book advice, browse jobs, and join events, using the reset flow on the login screen rather than any link in an unexpected email.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
