Data breach
Southeastern Oklahoma State University
- Records
- 582,315
- Breach date
- 19 August 2026Estimated
- Added
- 20 August 2026
What was exposed
7 types of data · 1 puts you at serious risk
- Email addresses582,315
- Names533,399
- Dates of birth325,698
- Phone numbers245,754
- Street addresses129,618
- Social security numbers92,644
- Vehicle VINs88
About this breach
The ransomware group Interlock has claimed responsibility for a cyberattack on Southeastern Oklahoma State University, a public university in Durant, Oklahoma. According to our investigation team, the listing covers 582,315 rows of data and was added to our index on August 20, 2026. Ransomware.live first recorded the group's leak-site entry on August 19, 2026, and estimates the underlying attack took place around July 31, 2026. The university disclosed a network disruption in late July but has not confirmed that student or employee data was stolen, so the group's claims remain unverified.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
July 30, 2026: The university reported a network disruption affecting campus systems in a Facebook post, according to ClassAction.org. The Durant campus closed on July 30, July 31, and August 3 while systems were restored, per the Cyber Incident Registry.
July 31, 2026: Ransomware.live estimates this as the date of the attack.
August 18, 2026: Ordinary campus operations had resumed, according to the Cyber Incident Registry.
August 19, 2026: Interlock listed Southeastern Oklahoma State University on its leak site, claiming it had published 710 GB of university data. The university has not confirmed the actor, the ransomware, or the data theft.
What Information Was Compromised?
Our analysis found the following data types in this breach: 582,315 email addresses, 533,399 names, 325,698 birthdays, 245,754 phone numbers, 129,618 street addresses, 92,644 Social Security numbers, and 88 vehicle VINs.
Not every individual is affected by every type of data listed here.
Interlock's leak-site listing, as summarized by Ransomware.live, describes student educational records including names, contact information, Social Security numbers, grades, enrollment data, financial aid information, disciplinary records, and medical information contained in educational records, as well as employee injury records. These descriptions come from the attackers and have not been independently verified. ClassAction.org reports the group claims records tied to more than 90,000 students, including student identification numbers and Forms 1095-C.
What Are the Potential Risks for Affected Individuals?
Social Security numbers and dates of birth are the building blocks of identity theft. Someone holding them can attempt to open bank accounts, apply for loans, or file fraudulent tax returns in a victim's name. Phone numbers and addresses enable convincing phishing calls, texts, and mail designed to look like legitimate university or financial communications.
Because the listing reportedly includes student records with financial aid information, affected students should watch for fraudulent student loan offers or scams that reference their enrollment. Email addresses in the breach can be used for targeted phishing that cites real campus details to appear credible.
What Is Southeastern Oklahoma State University Doing in Response?
The university reported the network disruption in late July, closed its Durant campus for three days, and restored normal operations by August 18. As of September 25, 2026, the school has not publicly confirmed whether any data was accessed or stolen during the incident, and no breach notification to affected individuals has been verified in sources reviewed. Affected individuals should monitor the university's website and official communications for updates.
What Should You Do If You Were Affected?
Check your credit reports from Equifax, Experian, and TransUnion, and consider placing a fraud alert or credit freeze.
File taxes early to reduce the chance of a fraudulent return in your name.
Be skeptical of calls, texts, or emails that reference the university, your enrollment, or your financial aid, and do not share personal information in response.
If you have a university account, change that password and any account where you reused it, and turn on multi-factor authentication where available.
Watch for scam debt-relief or loan-forgiveness offers that cite your student records.
