In 2025, Columbia University experienced a data breach related to its Morningside campus. The university confirmed that an unauthorized individual unlawfully acquired data from a restricted segment of its network. This incident was disclosed through an official statement from Columbia University and was also reported by various news outlets.
The breach affected over 2.5 million applicants, students, staff, and their families. Exposed data types included Social Security Numbers (SSNs), passport scans, citizenship status, admissions records (from the 1990s to 2024), UNI credentials, financial aid data (FAFSA), payroll files, bank and routing numbers, disciplinary records, immunization records, disability accommodations, and demographic information such as race and ethnicity. Columbia began sending notification letters on a rolling basis starting August 7, 2025. The full extent of the data theft is still being investigated.
Details about data breaches can emerge over time, and notifications to affected individuals may be delayed.