Monroe University revealed that hackers managed to gain access to its systems from December 9 to 23, 2024, exploiting security vulnerabilities that allowed the theft of personal, financial and medical information. The data breach affected a total of 320,973 people, according to an audit completed in September 2025.

Monroe was founded in 1933 and has grown into a private university with more than 9,000 students annually. The institution's size and geographic spread mean the breach affects students, staff and alumni in different parts of the world.
See also: AZ Monica Hospital: Servers offline due to cyberattack
Monroe University: What data was exposed
The University clarified that the stolen information includes sensitive data, such as:
- Names and dates of birth
- Social security, passport and ID numbers
- Driver's license numbers
- Medical and insurance information
- Email and financial account details
- Student data
The information exposed varies per person, but the extent of the breach makes it clear that nearly every aspect of the affected individuals' personal and professional lives was at risk.

Notifications and protection measures
The university began sending out alerts on Jan. 2, recommending monitoring credit reports and bank accounts for signs of fraud. It also offers free credit monitoring for one year through its Cyberscout.
See also: Central Maine Healthcare: Data breach affects over 145,000 people
The lack of immediate comment from university representatives leaves unanswered questions about how the hackers gained access and what actions were taken to strengthen security after the attack.
Ransomware history and attack patterns
Monroe University is no stranger to cyberattacks. Previously, when it was known as Monroe College, it was hit by ransomware with attackers demanding 170 bitcoins (about $2 million at the time) to decrypt files.
Similar attacks have hit several US universities in recent months. The University of Hawaii announced last month that Cancer Center was hacked in August 2025. Baker University revealed a data breach involving 53,000 people, while universities including Harvard University, Princeton University and the University of Pennsylvania have also suffered theft of personal data from students, donors and staff.

The problem of security in academic institutions
The attacks on Monroe and other universities show that academic institutions remain particularly vulnerable. The volume of data, connections with international partners, and the use of multiple platforms create an “open window” for malicious actors. At the same time, the increased use cloud services and digital applications increases the attack surface, making universities attractive targets for ransomware and identity theft.
See also: Endesa Spain: Data breach affects customers
The data breach at Monroe University highlights the importance of cybersecurity in academia. With over 320,000 victims, the case shows how vulnerable universities can become when they don’t invest enough in protection and monitoring. Monroe offers free credit monitoring services and identity protection advice, but the incident serves as a wake-up call for all educational institutions: data security is no longer just a technical issue, but a critical safeguard for students, staff and the institution’s own reputation.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
