Data breach
Campbell University
- Records
- 1,132,341
- Breach date
- 11 April 2026Estimated
- Added
- 30 July 2026
What was exposed
10 types of data · 6 more reported · 3 put you at serious risk
- Names1,132,341
- Email addresses581,878
- Street addresses440,940
- Dates of birth291,355
- Phone numbers206,943
- Social security numbers156,591
- Driving licence numbers224
- Vehicle VINs203
- Passport numbers167
- Licence plates158
- Bank account numbersReported, not counted
- Card numbersReported, not counted
- Medical recordsReported, not counted
- Medical diagnosesReported, not counted
- Insurance detailsReported, not counted
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Campbell University, a private university in Buies Creek, North Carolina, disclosed a data breach involving unauthorized access to one of its cloud-based data storage platforms. According to the university's data notice, the intrusion occurred between March 31 and April 1, 2026, and was discovered on April 1. The university says existing protections kept the incident isolated to that single platform, and no other campus systems were affected.
The investigation team indexed more than 1.13 million records tied to this listing, including more than 156,000 Social Security numbers and nearly 582,000 email addresses. The dark web intelligence platform DeXpose reported that a threat actor calling itself Incransom claimed responsibility for stealing 500 GB of information from the university. The university's notice does not confirm that claim, and no ransom amount has been verified.
March 31 to April 1, 2026: Unauthorized access to a Campbell University cloud-based data storage platform occurred, according to the university's data notice.
April 1, 2026: Campbell University discovered the incident and began an investigation.
April 12, 2026: The breach was first publicly noted by DeXpose, which reported that Incransom claimed to have stolen 500 GB of data.
May 29, 2026: The university reported the breach to the U.S. Department of Health and Human Services, per ClassAction.org.
June 5, 2026: Notification letters began mailing to affected individuals, along with offers of complimentary credit monitoring for those whose Social Security numbers were exposed, according to The HIPAA Journal.
What Information Was Compromised?
Our analysis found the following data types in this breach: 1,132,341 names, 581,878 email addresses, 440,940 street addresses, 291,355 dates of birth, 206,943 phone numbers, 156,591 Social Security numbers, 224 driver's license numbers, 203 vehicle VINs, 167 passport numbers, and 158 vehicle plate numbers.
The university's notice describes additional categories of information that may have been present in the affected system, including medical record numbers, provider or facility names, medical conditions, diagnoses and treatment information, lab results, prescriptions and medications, mental health information, health insurance information, financial account information, debit and credit card information, student identification numbers, IRS identity protection PINs, digital signatures, geolocation data, and usernames and access information for non-financial accounts.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of Social Security numbers, dates of birth, and street addresses is enough for criminals to attempt identity theft, open fraudulent accounts, or file fake tax returns. The medical and health insurance information described in the university's notice carries additional risk, since medical identity theft can be harder to untangle than financial fraud and can affect care records. Stolen email addresses and phone numbers can also fuel targeted phishing, in which attackers pose as the university, a health insurer, or a bank using details they know to be true. The university has stated it has no evidence that any information has been misused so far, but that is not a guarantee it will stay that way.
