Columbia University Data Breach Exposes 2.5 Million Applicants' Data

Columbia University Data Breach Exposes 2.5 Million Applicants' Data

First seen 4 Jun 2026, 17:25 UTC Gadgetreviewcloudstoragesecurity.comwww.cuit.columbia.edu 81% similarity 67.0

Article Content

Browse articles
ThreatCluster

In June 2025, Columbia University suffered a significant data breach, initially misreported as a technical failure. The breach, attributed to a politically motivated hacktivist, resulted in the exfiltration of 460 GB of sensitive data, impacting 868,969 individuals, including many with no direct ties to the university. The stolen data included Social Security numbers, financial aid records, and academic histories of over 2.5 million applicants. The attacker claimed the breach aimed to expose post-affirmative action admissions practices. Columbia detected the breach in late June but did not notify the public until July, leaving many victims confused about their compromised data. A forensic investigation is ongoing, but no specific details about the attack vector or vulnerabilities exploited have been disclosed. The incident raises concerns about the retention of sensitive personal data by educational institutions.

Key Points: • Columbia University experienced a major data breach affecting 868,969 individuals. • The breach involved the theft of 460 GB of sensitive data, including Social Security numbers. • The attacker claimed to expose issues related to post-affirmative action admissions practices.

ThreatCluster AI

Timeline

2024-06-25
CVE-2024-37085 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-06-24
Columbia University suffers data breach
A cyberattack led to an outage across Columbia's Morningside campus, affecting core services.
cloudstoragesecurity.com
2025-07-01
Breach confirmed as targeted cyberattack
Columbia University confirmed the incident was a targeted cyberattack by an external actor.
cloudstoragesecurity.com
2025-07-01
Public notification of breach delayed
Columbia did not notify the public about the breach until July, weeks after detection.
Gadgetreview
Recent
Forensic investigation underway
A third-party cybersecurity firm is conducting a forensic investigation in coordination with law enforcement.
cloudstoragesecurity.com

Community

Browse all →