HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALHEALTH_BASICHighContained
Columbia University
bd_1de0d58aeabac377 · schema v1 · pii pii-v1
Full breach record for Columbia University →Columbia University notified the NH Attorney General of a cyber incident where an unauthorized third party accessed the network around May 16, 2025, and exfiltrated personal data including names, DOBs, and SSNs. The breach was detected on June 24, 2025. 2,340 New Hampshire residents were notified on August 7, 2025, and offered 24 months of credit monitoring.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_2337be0c0546ca35Iowa State AGfiled 2025-08-08(4d gap)Verified
- bd_07533b0c85ac791cMaine State AGfiled 2025-08-07(5d gap)Candidate
- bd_2c8504262b9c10ebWashington State AGfiled 2025-08-07(5d gap)Verified
- bd_44bbed6c166a9c6dIndiana State AGfiled 2025-08-07(5d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 5d gap
- bd_82648491a36c0afcDelaware State AGfiled 2025-08-07(5d gap)Verified
- bd_88b5b3d68c5a023aMontana State AGfiled 2025-08-07(5d gap)Verified
- bd_9b1ee72034df1e55Vermont State AGfiled 2025-08-07(5d gap)Verified
- bd_d1103ca10d166462California State AGfiled 2025-08-07(5d gap)Verified
- bd_d5052bb9304189edSouth Carolina State AGfiled 2025-08-07(5d gap)Verified
- bd_f8f32a88711240f8Oregon State AGfiled 2025-08-07(5d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/columbia-university-20250812.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 12, 2025
- Raw hash
- 9b9dee381d1445fcda95afccb855971d79164f0ae39cea70a589ea24f33c4346
Reporting entity
- Name
- Columbia Universitynorm: columbia university
Victim entity
- Name
- Columbia Universitynorm: columbia university
Incident
- Discovered
- Jun 24, 2025
- Materiality determined
- —
- Notification sent
- Aug 7, 2025
- Affected individuals
- 2,340
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.