HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTEDUCATIONFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Columbia University
bd_d1103ca10d166462 · schema v1 · pii pii-v1
Full breach record for Columbia University →Columbia University experienced unauthorized access to its network starting May 16, 2025, discovered on June 24, 2025. An external actor exfiltrated files containing names, SSNs, DOBs, academic history, and some health/financial aid data. Patient records were not affected. The university engaged forensic experts, notified law enforcement, and is offering credit monitoring.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_07533b0c85ac791cMaine State AGfiled 2025-08-07Candidate
- bd_2c8504262b9c10ebWashington State AGfiled 2025-08-07Verified
- bd_44bbed6c166a9c6dIndiana State AGfiled 2025-08-07Verified
- bd_82648491a36c0afcDelaware State AGfiled 2025-08-07Verified
Show 6 more filings ↓Show fewer ↑up to 5d gap
- bd_88b5b3d68c5a023aMontana State AGfiled 2025-08-07Verified
- bd_9b1ee72034df1e55Vermont State AGfiled 2025-08-07Verified
- bd_d5052bb9304189edSouth Carolina State AGfiled 2025-08-07Verified
- bd_f8f32a88711240f8Oregon State AGfiled 2025-08-07Verified
- bd_2337be0c0546ca35Iowa State AGfiled 2025-08-08(1d gap)Verified
- bd_1de0d58aeabac377New Hampshire State AGfiled 2025-08-12(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-606745
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 7, 2025
- Raw hash
- 967df5bc78c00c382504fa6dab2881ce21aef482a4f247131880baccb73e26f2
Reporting entity
- Name
- Columbia Universitynorm: columbia university
Victim entity
- Name
- Columbia Universitynorm: columbia university
Incident
- Discovered
- Jun 24, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEDUCATIONFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.