Data breach
NYU
- Records
- 3,160,701
- Breach date
- 22 March 2025Estimated
- Added
- 25 March 2025
What was exposed
5 types of data · 2 more reported
- Names1,071,423
- Email addresses984,634
- Education history815,218
- Grades812,972
- Qualifications3,193
- Social security numbersReported, not counted
- PostcodesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
On March 22, 2025, a hacker took control of New York University's homepage for roughly two hours and posted downloadable files containing records on millions of people who applied to the school, according to Washington Square News. The defaced page displayed charts of SAT, ACT, and GPA averages broken down by race, framed as a claim that NYU continued race-sensitive admissions after the Supreme Court barred the practice in 2023. Alongside the charts sat four CSV files with admissions data spanning decades. According to our investigation team, the indexed dataset contains 3,160,701 rows.
NYU's own notification letter, filed with the California Attorney General, later confirmed a broader intrusion: an unauthorized actor took files from the university's network between October 20, 2024, and March 21, 2025.
March 22, 2025: A hacker redirects NYU's homepage and posts downloadable CSV files with applicant data going back decades; the page is first flagged on Reddit around 10:30 a.m. and restored by noon.
March 25, 2025: The first of several proposed class action lawsuits is filed against NYU over the breach.
April 1, 2025: Washington Square News reports NYU faces ten class action lawsuits filed by individual applicants.
May 9, 2025: NYU completes its review of the taken files, identifying affected individuals.
May 23, 2025: NYU begins mailing breach notification letters, per the notice filed with the California Attorney General.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, names, and education records, including grade point averages for hundreds of thousands of individuals and education type entries for a smaller subset.
According to Washington Square News, the publicly posted files included test scores, majors, zip codes, demographic data, citizenship status, and Common Application details such as financial aid information and information about siblings and parents. Records reached back to 1978 and covered admitted and rejected applicants across all NYU schools, including NYU Abu Dhabi. Reporting noted the files did not appear to include phone numbers, home addresses, or Social Security numbers.
Separately, NYU's breach notification letter stated that its investigation found files containing names and Social Security numbers taken from its network, and offered affected recipients a free one-year Identity Defense membership.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Admissions records may seem less sensitive than payment data, but the combination of names, emails, test scores, GPAs, and family financial details is valuable for fraud. Attackers can use it to craft convincing phishing emails that impersonate universities, lenders, or scholarship programs, since the details make the messages look legitimate. The class action lawsuits argue the exposed information is often enough for criminals to work backward to phone numbers or addresses. For anyone whose Social Security number was involved, per NYU's notice, the risks extend to identity theft, fraudulent loan applications, and tax fraud.
What Is NYU Doing in Response?
NYU said its IT team responded immediately, took down the attacker's page, reported the incident to law enforcement, and hired external investigators to review its systems. In a university-wide email about six hours after the breach, senior administrators Martin Dorph and Don Welch confirmed those steps. A follow-up email five days later said NYU IT and a cybersecurity consultant were evaluating what personal information was exposed. The university also called the charts posted during the breach inaccurate and misleading without detailing how. Criticism followed: reporting noted that alumni and unenrolled applicants, who make up most of those affected, initially received no direct communication.
What Should You Do If You Were Affected?
If you applied to NYU at any point in recent decades, treat this breach as relevant to you. Watch for NYU's notification letter, which includes an activation code for the free one-year Identity Defense membership. Beyond that, place a free security freeze with Equifax, Experian, and TransUnion, review your credit reports at annualcreditreport.com, and be skeptical of unsolicited emails referencing your application, test scores, or financial aid.
In the news
- Washington Square News: Over 3 million applicants' data leaked on NYU's websitenyunews.com (opens in a new tab)
- Washington Square News: NYU hit with 10 class action lawsuitsnyunews.com (opens in a new tab)
- NYU breach notification letter filed with the California Attorney Generaloag.ca.gov (opens in a new tab)
- Strauss Borrelli PLLC: NYU data breach investigationstraussborrelli.com (opens in a new tab)
