Data breach
Dartmouth College
- Records
- 163,306
- Breach date
- 13 November 2025Estimated
- Added
- 18 December 2025
What was exposed
5 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses163,306
- Phone numbers36,888
- Social security numbers25,413
- Names1
- Postcodes1
- Bank account numbersReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Dartmouth College has confirmed a data breach tied to the Clop extortion group's exploitation of a zero-day vulnerability in Oracle's E-Business Suite software. According to the college's notification letters and filings with state attorneys general, an unauthorized actor took files from Dartmouth's Oracle EBS environment between August 9 and August 12, 2025. The attack was part of a wider campaign that hit more than 100 organizations worldwide, including Harvard University and the University of Pennsylvania.
The investigation team indexed the breach listing with an estimated attack date of November 13, 2025, and a dataset of 163,306 rows, added to our records on December 18, 2025. The Clop gang later published roughly 226 GB of archives allegedly stolen from the college on its dark web leak site, as reported by SecurityWeek and BleepingComputer.
August 9–12, 2025: An unauthorized actor exploited an Oracle E-Business Suite zero-day vulnerability (CVE-2025-61882) to take files from Dartmouth's environment, according to the college's breach notification.
October 30, 2025: Dartmouth's investigation identified files containing names, Social Security numbers, and financial account information.
November 24, 2025: The college mailed notification letters and filed breach notices with state attorneys general, including Maine, where 1,494 residents were reported affected.
November 25–26, 2025: Clop listed Dartmouth among victims on its leak site, and security outlets confirmed the leaked data.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers (25,413 records), email addresses (163,306 records), and phone numbers (36,888 records). The indexed data also includes names and zip codes, though our investigation team could not determine how many of each are present.
Dartmouth's own notification letter, filed with the California Attorney General, additionally confirms that financial account information was taken alongside names and Social Security numbers. Reporting by The Dartmouth indicates state filings also reference birth dates and bank account information.
Not every individual is affected by every type of data listed here.
The total number of affected individuals has not been fully disclosed. State filings point to at least 1,494 Maine residents and more than 31,000 New Hampshire residents, and The Dartmouth reported that more than 40,000 people were affected based on the notices. The 163,306 rows in the indexed dataset may reflect multiple records per person or duplicate entries.
What Are the Potential Risks for Affected Individuals?
Social Security numbers combined with names and financial account information are among the most dangerous data combinations in a breach. Exposed SSNs can be used for identity theft, fraudulent tax returns, new-account fraud, and loan applications in someone else's name. Bank account details raise the risk of direct financial fraud. Email addresses and phone numbers can fuel targeted phishing and social engineering, since attackers with leaked details appear more convincing. Because Clop published the stolen files publicly, the data may circulate among other criminals indefinitely.
What Is Dartmouth College Doing in Response?
Dartmouth says it secured its environment after discovering the incident, notified law enforcement, and launched an investigation. The college implemented all publicly available patches for the Oracle EBS software and said it will continue vetting vendors' data security practices. It is offering affected individuals a complimentary one-year membership to Experian IdentityWorks, which includes credit monitoring and identity theft protection. A spokesperson told The Dartmouth that the investigation was ongoing and that Dartmouth would notify and support affected individuals in accordance with applicable law.
What Should You Do If You Were Affected?
If you received a notification letter, enroll in the offered Experian IdentityWorks membership. Consider placing a free security freeze with Equifax, Experian, and TransUnion, which blocks new credit accounts from being opened in your name. Order your free credit reports at annualcreditreport.com and review them for unfamiliar accounts or inquiries. Watch for phishing emails or calls that reference the breach, and never share sensitive information in response to unsolicited contact. Dartmouth has set up a dedicated assistance line at 1-800-374-9811 for questions about the incident. If you suspect identity theft, file a report with the Federal Trade Commission at identitytheft.gov and with your local police.
In the news
- BleepingComputer: Dartmouth College confirms data breach after Clop extortion attackbleepingcomputer.com (opens in a new tab)
- SecurityWeek: Dartmouth College Confirms Data Theft in Oracle Hacksecurityweek.com (opens in a new tab)
- The Dartmouth: More than 40,000 hit by Dartmouth data breachthedartmouth.com (opens in a new tab)
- Maine Attorney General breach notification filingmaine.gov (opens in a new tab)
- Dartmouth College notice of data breach (California AG)
