University of the People
ent_10b5b6f7caa9d7961942a12a
Disclosures
8
State AG · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,650
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of the People
- Normalized
- university of the people— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- Washington State AGas victim2025-11-14
University of the People reported unauthorized access to a database affecting 1,650 Washington residents. Access occurred between Sept 9 and Oct 23, 2025. Data included names, DOBs, and student IDs. No financial or SSN data impacted. Forensic investigation engaged.
- Massachusetts State AGas victim2023-04-13
University of the People reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-04-13. 76 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2023-04-05
University of the People notified the California AG of a data breach where unauthorized third parties accessed and potentially exfiltrated files from its SharePoint platform between January 2 and January 10, 2022. The university learned of the incident in mid-January 2022. Affected data may include personal information such as names, addresses, and potentially Social Security numbers. The university engaged third-party experts, secured its network, and offered one year of credit monitoring to affected individuals.
- Maine State AGas victim2023-04-05
University of the People reported a data breach affecting 11 Maine residents. The incident, which occurred between January 2, 2022, and January 10, 2022, was discovered on March 21, 2023. The breach was described as an external system breach (hacking) and resulted in the compromise of Social Security numbers. Affected individuals were notified in writing on March 24, 2023, and offered identity theft protection services.
- Vermont State AGas victim2023-04-04
University of the People notified consumers of a data security incident in mid-January 2022. Unauthorized third parties accessed or exfiltrated files from a SharePoint platform between January 2 and January 10, 2022. The files contained personal information, including names and government IDs. UoPeople engaged third-party experts, enhanced security, and offered one year of credit monitoring.
- Montana State AGas victim2023-04-04
University of the People notified Montana residents of a data security incident in mid-January 2022. Unauthorized third parties accessed or exfiltrated files from a SharePoint platform between Jan 2-10, 2022. The incident potentially exposed personal information of applicants and students. UoPeople engaged third-party experts, enhanced security, and offered one year of credit monitoring.
- New Hampshire State AGas victim2023-04-04
University of the People reported unauthorized access to its SharePoint platform between Jan 2-10, 2022. The incident impacted 19 New Hampshire residents' PII. UoPeople engaged forensic experts, notified law enforcement, changed passwords, and offered credit monitoring.
- Indiana State AGas victim2023-03-24
University of the People reported a data breach to the Indiana Attorney General. The breach occurred on 2022-01-02 and was reported on 2023-03-24. 80 Indiana residents were affected.