Data breach
Columbia University
- Records
- 345,746
- Breach date
- 24 June 2025Estimated
- Added
- 30 June 2025
What was exposed
8 types of data · 3 more reported · 1 puts you at serious risk
- Email addresses345,746
- Dates of birth1
- Grades1
- Ethnic groups1
- Names1
- Phone numbers1
- Race1
- Social security numbers1
- GenderReported, not counted
- Insurance detailsReported, not counted
- Medical recordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A hacker stole personal information from Columbia University in a cyberattack that disrupted the school's computer systems in late June 2025. According to our investigation team, the incident is estimated to have occurred on June 24, 2025, when Columbia experienced a technical outage that took down services including email and course platforms. The listing indexes 345,746 email addresses tied to the breach. Reporting from Bloomberg and The New York Times attributed the attack to a "hacktivist" who claimed the theft was meant to expose whether Columbia still used race-conscious admissions after the Supreme Court barred the practice in 2023. The university later reported to state officials that roughly 870,000 people were affected, including applicants with no current Columbia affiliation.
On or about May 16, 2025: According to Columbia's notice filed with the Iowa Attorney General, an unauthorized third party gained access to the university's network through a publicly exposed system.
June 24, 2025: Columbia discovered a technical outage, activated incident response protocols, notified law enforcement, and launched an investigation with FBI assistance and the cybersecurity firm CrowdStrike.
July 1, 2025: Bloomberg and The New York Times reported that a person claiming responsibility for the hack had provided sample stolen data, which Bloomberg verified for eight students and alumni.
August 7, 2025: Columbia began mailing formal notification letters to affected individuals.
September 21, 2026: The Columbia Spectator reported that Columbia agreed to pay $16.1 million to settle a consolidated class action lawsuit over the breach.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (345,746 records), and Social Security numbers, names, dates of birth, phone numbers, race or ethnic group, and education GPA, for which our listing does not include a count.
According to Columbia's notification letter, which The Independent published, the affected data also included contact details, demographic information such as gender and citizenship status, academic history including test scores and admission decisions, financial aid status and awards, tuition information, and any insurance-related and health information individuals shared with the university.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Social Security numbers and dates of birth are the most dangerous items in this breach, because criminals can use them to open accounts, file fraudulent tax returns, or impersonate someone in official processes. Admission decisions, grades, financial aid details, and health-related information cannot be changed like a password, and their exposure can enable targeted phishing that references real personal history. Columbia has said it has no evidence of identity theft or fraud stemming from the incident, but the risk from stolen Social Security numbers can persist for years.
What Is Columbia University Doing in Response?
Columbia blocked the intruder's access, took certain network ports offline, reset passwords for compromised accounts, and deployed additional endpoint detection tools, according to its notice to state attorneys general. The university offered 24 months of free credit monitoring and identity theft protection through Kroll, set up a dedicated call center, and began mailing notification letters on August 7, 2025. It also reported that it has removed prospective students' Social Security numbers from its systems. In September 2026, the university agreed to a $16.1 million settlement covering credit monitoring and up to $8,500 in reimbursement of out-of-pocket losses for class members.
What Should You Do If You Were Affected?
Enroll in the free credit monitoring through Kroll if you received a notification letter, and use the dedicated call center at (866) 819-7006 with questions.
Check your credit reports for accounts or inquiries you do not recognize, and consider placing a free security freeze with the three major credit bureaus.
Watch for phishing emails or calls that reference your Columbia application, financial aid, or the breach itself, and avoid clicking links in unexpected messages.
If you filed taxes recently, consider an IRS Identity Protection PIN to block fraudulent return filings.
Review the settlement terms if you were affected, since the deadline to file claims will follow the court's approval of the deal.
In the news
- Bloomberg: Columbia University Applicants' Personal Data Stolen by Hackerbloomberg.com (opens in a new tab)
- The New York Times: Columbia Cyberattack Appears Politically Motivatednytimes.com (opens in a new tab)
- Columbia Spectator: Nonaffiliates' personal data stolen in June 2025 cyberattackcolumbiaspectator.com (opens in a new tab)
- Columbia Spectator: Columbia to settle June 2025 data breach lawsuit for $16.1 millioncolumbiaspectator.com (opens in a new tab)
