Stanford University
ent_e43d83954730f399
Disclosures
23
State AG · Leak Site · HHS OCR · 8 jurisdictions
Multi-filing incidents
5
incidents joining 2+ filings here
Max affected reported
56,500
nationwide · HHS OCR CA
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Stanford University
- Normalized
- stanford university— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- stanford.edu
Disclosure history (23)newest first
- Massachusetts State AGas victim2024-03-11
Stanford University reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-03-11. 98 Massachusetts residents were affected.
- Indiana State AGas victim2024-03-11
Stanford University reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-12 and was reported on 2024-03-11. 20 Indiana residents were affected. 27,000 individuals affected in total.
- California State AGas victim2024-03-11
Stanford University's Department of Public Safety experienced a ransomware attack. Unauthorized access occurred between May 12, 2023, and September 27, 2023, when the incident was discovered. Personal information, including names and other operational data, may have been impacted. The university notified law enforcement, engaged forensic investigators, and terminated unauthorized access. Identity theft protection services are being offered to affected individuals, including minors.
- Vermont State AGas victim2024-03-11
Stanford University's Department of Public Safety experienced a ransomware attack between May 12 and September 27, 2023. Unauthorized access was gained to the network, potentially impacting personal information including names and other identifiers. Stanford notified law enforcement, engaged forensic investigators, and offered 24 months of identity theft protection. Approximately 9 Rhode Island residents were identified as affected.
- Maine State AGas victim2024-03-11
Stanford University reported an external system breach (hacking) occurring on May 12, 2023, discovered on September 27, 2023. The incident compromised names and Social Security Numbers of 27,000 individuals, including 3 Maine residents. Stanford notified affected individuals in writing on March 11, 2024, and provided 24 months of credit monitoring and identity protection services through IDX and TransUnion.
- GLOBALLeak Siteas victim2023-10-27
Stanford University is one of the world's leading research universities. Stanford is known for its entrepreneurial character, drawn from the legacy of its founders, Jane and Leland Stanford, and its relationship to Silicon Valley. Soon the university will be also known for 430Gb of internal data leaked online. Private information, confidential documents etc. Who is interested - contact us in messages section.
- Massachusetts State AGas victim2023-02-17
Stanford University reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-02-17. 28 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2023-02-17
Stanford University notified applicants that a misconfigured folder on its Department of Economics website exposed Ph.D. application files from Dec 5, 2022, to Jan 24, 2023. Data included names, DOB, addresses, and education records. Two downloads occurred. Stanford restricted access, updated security policies, retrained staff, and offered IDX identity protection services.
- GLOBALLeak Siteas victim2022-12-22
Stanford University
- Montana State AGas reporting2021-06-25
Stanford School of Medicine notified Montana residents of a data breach involving its third-party file-sharing vendor, Accellion. Suspicious activity was detected on Jan 21, 2021, and stolen files were posted online on March 29, 2021. The incident involved PII. Stanford engaged the FBI and offered credit monitoring.
- Montana State AGas reporting2021-06-25
Stanford School of Medicine notified Montana residents of a data breach involving its third-party file-sharing vendor, Accellion. Suspicious activity was detected on Jan 21, 2021, and stolen files were posted online on March 29, 2021. The incident involved PII. Stanford engaged the FBI and offered credit monitoring.
- Massachusetts State AGas victim2021-06-16
Stanford University School of Medicine reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-06-16. 34 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2021-05-28
Stanford University School of Medicine notified the New Hampshire Attorney General on May 28, 2021, of a security incident involving its third-party file-sharing service, Accellion FTA. Suspicious activity was detected on January 21, 2021. On April 23, 2021, Stanford discovered that data for 4 New Hampshire residents was exfiltrated and made available online. Stanford notified the FBI, took the system offline, and is offering credit monitoring services.
- Maine State AGas victim2021-05-28
Stanford University School of Medicine experienced an external system breach on January 21, 2021, which was discovered on April 23, 2021. The incident resulted in unauthorized access to individuals' names and Social Security numbers. In response, the university provided written notification to affected individuals on May 28, 2021, and offered 12 months of credit monitoring and identity theft resolution services through IDX.
- CALIFORNIAHHS OCRas victim2021-05-28
Stanford University School of Medicine reported to HHS on 2021-05-28 a Hacking/IT Incident affecting 2,063 individuals. Breached information located on Network Server. A business associate experienced a cyber-attack exposing ePHI including names, addresses, DOBs, SSNs, and diagnoses. CE offered identity protection and credit monitoring.
- Indiana State AGas victim2021-05-28
Stanford University School of Medicine reported a data breach to the Indiana Attorney General. The breach occurred on 2021-01-21 and was reported on 2021-05-28. 15 Indiana residents were affected.
- California State AGas victim2017-12-22
Stanford University notified individuals that personal information, including names, passport numbers, visa numbers, health insurance details, and Social Security numbers, was accessible to GSB faculty, staff, and students due to incorrect folder permissions on a shared file server. The exposure occurred between 2000 and early December 2017. The University Privacy Office received a report on October 27, 2017. Files were removed, and credit monitoring was offered.
- California State AGas victim2017-12-01
Stanford University notified the California Attorney General of a data breach involving employee personal information. A report containing names, dates of birth, Social Security Numbers, and salary data was accessible to Graduate School of Business faculty, staff, and students from mid-September 2016 to early March 2017 due to incorrect folder permissions. The IT team discovered the permission error on February 23, 2017, and secured the folders by March 3, 2017. The University Privacy Office was notified later in 2017. Stanford engaged a forensics firm and is offering credit monitoring to affected employees.
- Massachusetts State AGas victim2016-06-20
Stanford University reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-06-20. 29 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2016-06-16
Stanford University notified the NH AG of a breach at third-party vendor Equifax's W2-Express system. Unauthorized access occurred likely starting late Jan/early 2016 using stolen SSNs/DOBs. Discovered April 4, 2016. Compromised data included names, SSNs, addresses, and W-2 info. 2 NH residents affected. FBI and IRS notified. Credit monitoring offered.
- California State AGas victim2016-06-13
Stanford University notified affected individuals that their W-2 forms were improperly downloaded from Equifax's W-2Express service by an unauthorized person using valid credentials (SSN and DOB). The incident was discovered on April 4, 2016, after employees reported fraudulent tax returns. The attack occurred in late March 2016. Stanford disabled the service, engaged law enforcement, and offered credit monitoring. Data exposed included names, addresses, SSNs, DOBs, and wage/tax information.
- CALIFORNIAHHS OCRas reporting2013-01-23
Stanford School of Medicine (SOM) and Stanford Children's Hospital (SCH, formerly Lucile Packard Children's Hospital) reported to HHS on 2013-01-23 a Theft affecting 56,500 individuals. On January 9, 2013, a SOM workforce member's password-protected but unencrypted laptop was stolen from their vehicle. The ePHI included demographic and clinical information related to SCH patient care and SOM research. No evidence of unauthorized access was found. Breached information located on Laptop.
- California State AGas reporting2013-01-18
Stanford School of Medicine and Lucile Packard Children’s Hospital reported the theft of a physician’s laptop on January 9, 2013, following a car break-in. The laptop contained limited patient health information, including names, dates of birth, and contact information for some children, but no SSNs or financial data. The device was password-protected. The organization notified affected individuals and offered one year of complimentary identity protection services via AllClear ID.