Data breach
Monmouth University
- Records
- 2,119,029
- Breach date
- 3 March 2026Estimated
- Added
- 21 July 2026
What was exposed
10 types of data · 4 more reported · 3 put you at serious risk
- Email addresses2,119,029
- Names1,623,996
- Street addresses1,013,762
- Phone numbers579,965
- Dates of birth460,991
- Social security numbers117,759
- Licence plates4,035
- Vehicle VINs549
- Passport numbers353
- Driving licence numbers109
- Bank account numbersReported, not counted
- Government IDsReported, not counted
- Medical recordsReported, not counted
- Insurance detailsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
The data breach at Monmouth University involved the theft of a large volume of personal information from the private university in West Long Branch, New Jersey. The extortion group Pear, also known as Pure Extraction and Ransom, claimed responsibility and listed the university on its leak site. According to our investigation team, the listing contains more than 2.1 million rows of data, including Social Security numbers, dates of birth, and contact details for students, employees, and others connected to the school.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
February 5–13, 2026: The breach window during which unauthorized access occurred, according to a Texas Attorney General data security breach filing published on July 1, 2026.
March 13, 2026: University President Patrick Leahy notified current students and employees by email about a cybersecurity incident. The university said it engaged cybersecurity experts and notified the FBI and the Department of Education.
March 26, 2026: Pear claimed responsibility on its leak site, stating it had stolen roughly 16 terabytes of data. The claim was reported by Comparitech and tracked by ransomware.live.
Late March 2026: Three federal class action lawsuits were filed in the US District Court for the District of New Jersey by former students, as reported by The Outlook, the student newspaper.
May 29, 2026: The university formally discovered the breach, according to the Texas AG filing.
July 1, 2026: The incident appeared in the Texas Attorney General breach report, which identified 164,041 affected individuals. Notification was provided by US Mail.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers (117,759), names (1,623,996), email addresses (2,119,029), phone numbers (579,965), dates of birth (460,991), street addresses (1,013,762), passport numbers (353), driver's license numbers (109), vehicle identification numbers (549), and vehicle plate numbers (4,035).
The Texas AG filing and related reporting also identified financial account information, medical information, health insurance information, and government-issued ID numbers among the compromised data. Pear's leak-site claim, which the university has not confirmed, described financial records, student files, health records, data on minors, and files from cloud storage services.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Social Security numbers combined with names, addresses, and dates of birth are the core ingredients for identity theft. Thieves can use them to open credit accounts, file fraudulent tax returns, or impersonate victims with government agencies and healthcare providers.
The reported presence of medical and health insurance information adds a further risk of medical identity fraud, which can be harder to detect and untangle than standard credit fraud. Email addresses and phone numbers also make affected people targets for phishing, in which attackers pose as the university or a credit bureau to extract more information or money.
What Is Monmouth University Doing in Response?
In a statement reported by The Outlook, the university said it initiated response protocols upon learning of the incident, engaged cybersecurity experts, notified the FBI and the Department of Education, and believed the incident had been contained, with no operational disruption. Chief Information Officer John Sonn said the university was working to identify the specific information involved so it could notify affected individuals. On March 31, the university emailed students asking them to change their passwords after updating its password policy. Notification letters were sent by US Mail, per the Texas AG filing.
What Should You Do If You Were Affected?
Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion. A freeze is free and blocks most new credit accounts from being opened in your name.
Monitor your credit reports and bank and insurance statements for activity you do not recognize.
Watch for phishing emails or calls that reference the university and never share passwords or codes in response.
Change your Monmouth University password if you have not already, and avoid reusing that password elsewhere.
If you receive a notification letter, review any services it offers, and contact the university at support@monmouth.edu with questions.
In the news
- The Outlook: Lawsuits mount after data is breached in cybersecurity incidentoutlook.monmouth.edu (opens in a new tab)
- The Outlook: Monmouth becomes latest victim of massive cyberattackoutlook.monmouth.edu (opens in a new tab)
- Comparitech: H1 2026 education ransomware roundupcomparitech.com (opens in a new tab)
- ransomware.live: Pear group profileransomware.live (opens in a new tab)
- Almeida Law Group: Monmouth University data breach investigationalmeidalawgroup.com
