Personal data connected to the University of Oxford was exposed through a breach of a third-party platform, CareerConnect. As with so many incidents this year, the weak point wasn’t the institution itself but a supplier holding its data.
The takeaway
This is the supply-chain risk in a nutshell: you can run a tight ship internally and still be exposed by a vendor’s security gap. Every platform you hand data to becomes part of your attack surface.
Know which suppliers hold your data and what they hold, put security expectations into your contracts, and ask for evidence — Cyber Essentials, ISO 27001, breach history. We help clients build that supplier due-diligence into how they buy and manage third-party services.
Source: The Register, 6 June 2026.