Columbia University, specifically its Morningside campus, experienced a cyberattack on June 24, 2025. The university stated that a hacker stole data from a limited portion of its network. This incident is widely referred to as the Columbia University Data Breach.
The breach exposed sensitive data belonging to approximately 2.5 million applicants, dating back decades, and about 2 million current and former students, faculty, staff, and their families. The exposed data includes Social Security Numbers (SSNs), passport scans, citizenship status, dates and places of birth, home and campus addresses, email and phone numbers, academic transcripts, disciplinary records, financial aid data (FAFSA), bank accounts, payroll files, university IDs, and demographic information such as gender, race, and ethnicity. The university began mailing notification letters to affected individuals on August 7, 2025, on a rolling basis. A forensic investigation is being led by a third-party cybersecurity firm in coordination with law enforcement, and there is no ongoing network threat.
Details about data breaches can emerge over time, and notification processes can be delayed due to the complexity of investigations.