An unknown menace actor has stolen the delicate private, monetary, and well being data of practically 870,000 Columbia College present and former college students and staff after breaching the college’s community in Might.
Established in 1767 as King’s Faculty, Columbia College is a non-public Ivy League analysis college with a finances of $6.6 billion in 2024, over 20,000 staff, together with 4,700 educational workers, and over 35,000 enrolled college students throughout 19 colleges and particular applications.
The breach was found and reported to regulation enforcement authorities following an outage that affected a few of its methods on June 24, following an investigation with assist from exterior cybersecurity consultants.
In notification letters filed with the workplace of Maine’s Legal professional Basic on Thursday, August 7, the college stated that the data breach impacts 868,969 people, together with staff, candidates, present and former college students, and relations.
“Our investigation decided that, on or about Might 16, 2025, an unauthorized third-party gained entry to Columbia’s community and subsequently took sure information from our system,” Columbia College stated. “Thus far, we’ve got no proof that any Columbia College Irving Medical Middle affected person data had been affected.”
The college first confirmed the info theft final week in an announcement, following reviews that the alleged hacker claimed to have stolen 460 gigabytes of knowledge from the compromised methods.
On Wednesday, the college issued one other assertion, confirming that the stolen knowledge belongs to present and former college students, candidates, and a few Columbia staff.
Based on the letters despatched to affected people through the U.S. Postal Service, the stolen knowledge features a mixture of private, monetary, and well being data.
“The affected knowledge included your title, date of beginning, and Social Safety quantity, in addition to any private data that you just offered in connection along with your utility to Columbia, or that we collected throughout your research in case you enrolled,” the college added.
“This included your contact particulars, demographic data, educational historical past, monetary aid-related data, and any insurance-related data and well being data that you just shared with us.”
Whereas Columbia College has no proof that the info has been misused in identification theft or fraud makes an attempt, it is going to present two years of free credit score monitoring, fraud session, and identification theft restoration providers by way of Kroll to these impacted by this data breach.

Malware concentrating on password shops surged 3X as attackers executed stealthy Good Heist eventualities, infiltrating and exploiting important methods.
Uncover the highest 10 MITRE ATT&CK strategies behind 93% of assaults and the right way to defend towards them.



