In December 2025, Goodwin University Inc. experienced an external system breach. The Qilin ransomware group claimed responsibility for the incident later that month. An investigation concluded on March 20, 2026, revealing unauthorized file acquisition and access to sensitive data.
The breach involved names, addresses, Social Security Numbers, driver's license numbers, state identification card numbers, government-issued identification, personal health information, health insurance information, and dates of birth. At least 151 individuals were affected, including residents in Maine and Texas. The university began notifying affected consumers via U.S. Mail on April 16, 2026, and regulators, including the Maine Attorney General, were notified on May 4, 2026.
Details about the full scope of the breach and additional affected individuals may emerge as investigations continue. Notices to affected individuals may also be delayed.