Columbia University has disclosed a serious cyberattack incident, where an unauthorized third party accessed and extracted a significant amount of personal and financial data.
See also: Former student charged with Western Sydney University violations

The breach, which affects a large number of people associated with the university, was discovered after a technical outage in late June. According to a notification sent by the university, the incident was first detected on June 24, 2025, after some IT systems were disrupted.
An investigation, initiated with the help of outside cybersecurity experts, revealed that an unauthorized party had gained access to Columbia's network around May 16, 2025, and subsequently stole certain files. Columbia University has since reported the cyberattack to law enforcement.
The compromised information is extensive and includes names, dates of birth, and Social Security numbers. For current and prospective students, the stolen data could also include contact information, demographic information, academic records, financial aid applications, and any insurance or health information shared with the university.
See also: iClicker site hack targeted students via CAPTCHA

Columbia has said that, to date, there is no evidence that patient records from Columbia University Irving Medical Center were affected by the breach. While the university has not officially confirmed the total number of people affected in its public statements, the scope of the breach is significant. A notice to the Rhode Island Attorney General said that approximately 2,510 residents of that state may have been affected.
In response to the cyberattack, Columbia University is taking steps to strengthen its system security to prevent future incidents. The university is offering two years of free credit monitoring and identity restoration services through Kroll, a risk reduction company. Affected individuals are encouraged to sign up for these services and remain vigilant by regularly checking their financial statements and credit reports for any suspicious activity.
See also: Blue Shield of California: Millions of members' data leaked
Columbia has set up a dedicated call center to handle questions about the incident. The university is also providing guidance on how individuals can protect themselves, including placing fraud alerts or credit freezes with the major credit reporting agencies Equifax, Experian and TransUnion. Under U.S. law, consumers are entitled to one free credit report per year from each of these agencies.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
