On December 10, 2018, San Jose State University (SJSU) detected unauthorized access to a server operated by its auxiliary, SJSU Associated Students. The attacker accessed names, email addresses, usernames, and passwords. No SSNs, financial, or medical data were involved. SJSU blocked access, disabled credentials, and notified affected individuals on December 26, 2018. Remediation included migrating servers to SJSU infrastructure and conducting security assessments.