
Columbia University Data Breach: What Happened and the 2026 Update
Last Updated: September 3, 2026
The Columbia University data breach began well before the campus-wide IT disruption that made the incident visible.
Columbia's regulatory notification says an unauthorized third party gained access to its network on or about May 16, 2025 through a publicly exposed system. On June 24, the university experienced a major technical outage. The subsequent investigation determined that the attacker had accessed the network, disrupted operations, and removed data from admissions, financial aid, and certain employee databases.
The incident exposed highly sensitive information, including Social Security numbers, dates of birth, contact information, demographic information, academic history, financial-aid information, insurance-related data, and certain health information.
According to Columbia's official 2025 Cyber Incident FAQ, the university has no indication that patient records maintained by Columbia University Irving Medical Center were affected.
An August 2025 regulatory filing initially reported 868,969 affected individuals. Later, Columbia identified additional people whose information had been involved and continued issuing notifications. By June 2026, the university said that notification process had been completed.
Columbia has not published a definitive final victim total in its latest public update, so claims that exactly 2.5 million or 2.8 million individuals were affected should not be treated as confirmed facts.
That distinction is one of the most important corrections to early coverage of the Columbia University cyberattack.
Key Findings From the Columbia University Data Breach
| Finding | Current Evidence |
|---|---|
| Initial unauthorized access | Around May 16, 2025 |
| Initial access route | Publicly exposed system |
| Major outage | June 24, 2025 |
| Data theft | Confirmed |
| Initially reported affected population | 868,969 people |
| Additional affected individuals found later | Confirmed |
| Final 2026 affected-person count | Not publicly specified in Columbia's latest update |
| Data involved | Admissions, enrollment, financial aid and certain employee information |
| Social Security numbers | Confirmed |
| CUIMC patient records affected | Columbia says it has no indication they were |
| Identity theft or fraud linked to breach | Columbia says it has no evidence to date |
| Two years of credit monitoring | Offered through Kroll |
| Class-action litigation | Agreement in principle reported as of August 2026 |
| Confirmed $250 million breach settlement | Not established |
| Final settlement amount | Not publicly confirmed in the records reviewed |
This distinction between confirmed facts, regulatory disclosures, media reports, and attacker claims is essential when assessing a major cyber incident.
How the Columbia University Cyberattack Unfolded
The public story began on June 24, 2025, when students and employees suddenly encountered widespread problems with university IT services.
Authentication and online services were disrupted. Students and staff reported difficulty accessing email, coursework, video conferencing, and other university platforms.
There was another unusual element. Media reports described images of President Donald Trump appearing on public screens around campus.
That contributed to speculation that the outage was not a routine technical failure.
However, Columbia has not publicly established in its official breach notifications that the screen imagery was definitely caused by the same person responsible for the data theft.
By July, Columbia acknowledged that an unauthorized party had entered its network and that information had been stolen.
Columbia's official cyber incident information states that investigators working with outside cybersecurity experts and law enforcement concluded that an attacker accessed the network, disrupted operations, and stole data.
The Attack Started Before the June 24 Outage
One major gap in early reports was the breach timeline.
The June 24 outage was not when the attacker first entered Columbia's environment.
A notification filed with the Rhode Island Office of the Attorney General states that the unauthorized third party gained access on or about May 16, 2025 through a publicly exposed system.
The attacker then used that access to obtain information from student admissions, financial-aid, and certain employee databases.
That means the incident involved both:
Confidentiality risk, because sensitive information was stolen.
Availability risk, because university systems were disrupted.
For universities, that combination can be particularly damaging. One intrusion may affect identity systems, academic services, financial processes, administrative operations, and sensitive institutional data.
Organizations trying to identify similar weaknesses should examine more than individual vulnerabilities. A broader cyber resilience assessment can evaluate identity, network, endpoint, cloud, data protection, and incident-response controls together.
Who Was Behind the Columbia University Hack?
Early reporting described the attacker as a self-identified hacktivist claiming political rather than financial motivation.
The attacker reportedly said the purpose of the intrusion was to investigate whether Columbia continued using race in admissions decisions following the U.S. Supreme Court's 2023 rulings concerning race-conscious college admissions.
That motive should still be treated as an attacker claim, rather than an independently established explanation of everything the attacker intended to accomplish.
Reports surrounding the breach also discussed approximately 460 GB of allegedly stolen data.
Columbia's formal breach notifications confirm data theft, but the available official disclosures reviewed for this article do not independently establish the exact 460 GB figure.
This distinction matters.
A claim can appear across many cybersecurity websites without becoming an official finding.
2.5 Million Applications Did Not Automatically Mean 2.5 Million Victims
This became one of the most confusing numbers associated with the Columbia University data breach.
Early reporting referred to datasets involving approximately 2.5 million applications or application records covering many years.
That number was later repeated in some coverage as though 2.5 million individual people had been officially confirmed as breach victims.
Those measurements are not necessarily equivalent.
One individual may generate multiple records, and historical application databases can contain duplicated or related entries.
Columbia's initial regulatory notification reported 868,969 affected people.
The story continued into 2026.
Columbia later said that its ongoing review identified additional individuals who needed notification.
By June 2026, Columbia said notifications relating to the incident had been completed.
Because its latest public update did not provide a replacement final victim total, the exact final number should not be presented as confirmed unless Columbia or another authoritative filing establishes it.
What Information Was Exposed?
The compromised information went far beyond email addresses.
Depending on the individual, Columbia identified information related to admissions, enrollment, financial aid, and employment.
Potentially affected categories included:
- Names and contact information
- Dates of birth
- Social Security numbers
- Gender and ethnicity information
- Citizenship status
- Test scores and academic grades
- Admission decisions
- Expected graduation information
- Financial-aid status
- Financial-aid awards
- Tuition information
- Insurance-related information
- Certain health-related information
The exact information involved was not necessarily identical for every person.
That nuance matters.
A compromised database containing Social Security numbers does not automatically mean every person in the database had their Social Security number exposed.

Were Columbia University Medical Records Stolen?
Columbia says it has no indication that Columbia University Irving Medical Center patient records were affected.
Some university records involved certain health or insurance-related information, but that should not be confused with a confirmed compromise of CUIMC's patient medical-record environment.
These are different claims.
Separating them is important for legal accuracy and for people trying to understand their actual exposure.
Why University Data Is Valuable to Attackers
Higher-education institutions store types of information that many other organizations keep in separate environments.
Universities can hold:
- Academic histories
- Personal identifiers
- Financial-aid information
- Research data
- Employee records
- Applicant information
- Identity documents
- Authentication accounts
- Financial records
They also support unusually broad user populations.
Students, professors, employees, researchers, applicants, contractors, alumni, and external collaborators may all require access to different parts of the infrastructure.
That creates a complicated identity and security environment.
The Columbia incident also demonstrates why universities cannot prepare only for ransomware.
An attacker can create major privacy and operational consequences without encrypting every system.
Related incidents affecting education platforms show how quickly access problems can disrupt learning. Hoplon Infosec's coverage of the Canvas cyberattack during finals week examines how outages involving important academic platforms can affect coursework, examinations, and communication.
What the Breach Says About Endpoint and Identity Security
The regulatory disclosure identifies a publicly exposed system as the initial access point.
Once attackers reach an internet-facing asset, the next security question becomes whether that access can lead to important identities, applications, systems, and sensitive information.
Security therefore needs multiple defensive layers.
Modern endpoint security combines prevention with detection, monitoring, investigation, containment, and recovery rather than depending solely on traditional antivirus software.
Universities also need strong identity protections because one account may provide access to multiple interconnected services.
A Zero Trust endpoint security approach can reduce unnecessary implicit trust by continuously evaluating identity, device condition, authorization, and context before granting access.
Zero Trust does not guarantee that a breach cannot happen.
Its purpose is to reduce unnecessary access and limit what a compromised user or system can reach.
Did Columbia Fully Move to Zero Trust After the Breach?
There is not enough reliable public evidence to confirm the original claim that Columbia completed a full university-wide Zero Trust migration following the incident.
Columbia has described additional safeguards and enhanced security measures.
Regulatory disclosures also describe actions including blocking unauthorized access, taking certain ports offline, resetting compromised passwords, and strengthening endpoint detection and response capabilities.
Those are meaningful security improvements.
They should not, however, be described as proof that the entire university infrastructure completed a Zero Trust transformation unless Columbia publishes evidence confirming that claim.
Institutions improving detection after a breach may also use Extended Detection and Response, or XDR to correlate security signals across endpoints, identities, applications, and infrastructure.
What Columbia Said About Identity Theft and Fraud
Columbia's current public FAQ says it has no evidence of identity theft or fraud resulting from the incident.
That does not mean the compromised information has no value to criminals.
It means Columbia had not identified evidence connecting confirmed identity theft or fraud to the breach when its update was published.
Columbia offered affected individuals two years of complimentary credit monitoring and identity-restoration services through Kroll.
This is particularly relevant for individuals whose Social Security numbers or dates of birth were involved.
What Should Affected Students, Applicants, Employees, and Families Do?
Receiving a breach notification does not automatically mean someone has already stolen your identity.
It means information associated with you was identified among the affected records.
First, verify that any breach notification you receive is legitimate.
Then follow Columbia's official instructions for enrolling in the identity-monitoring services offered to eligible affected individuals.
Review financial accounts and credit reports for activity you do not recognize.
Because Social Security numbers were exposed for some victims, a credit freeze may also be appropriate.
The U.S. Federal Trade Commission's official identity-theft guidance explains how consumers can respond to compromised personal information and protect their credit.
Affected individuals should also:
- Use unique passwords for important accounts
- Enable multi-factor authentication
- Review account login activity
- Watch for suspicious password-reset emails
- Be cautious about calls referencing the breach
- Avoid clicking unexpected identity-monitoring links
- Verify messages through official Columbia channels
A real breach also gives scammers a believable story to use in phishing attacks.
Someone may pretend to be Columbia, Kroll, a financial institution, or a government agency.
If you accidentally enter credentials into a suspicious page, Hoplon Infosec's guide on what to do after you have clicked a phishing link explains how the response changes depending on whether you only opened a page, entered credentials, approved MFA, or downloaded a file.

What Changed in 2026?
One of the most important verified updates arrived in June 2026.
Columbia announced that it had completed notifications to people potentially affected by the 2025 cyber incident.
An unusual data-governance issue also emerged during the notification process.
Some recipients reportedly told Columbia that they had no known relationship with the university.
Columbia investigated and explained that certain information appeared to have reached the university through historical student recruitment services.
Prospective students may have shared information through services used to send test scores or request information about universities, colleges, and scholarship opportunities.
The university also said Social Security numbers belonging to some of those individuals had been removed or were being removed from its systems where legally permitted.
That finding adds an important lesson about data retention.
Organizations need to understand not only data belonging to current users but also information received through historical services, old programs, third-party platforms, and previous recruitment processes.
The 2026 Lawsuit Update
The earlier draft stated that Columbia had reached a $250 million class-action settlement covering 2.8 million affected people.
That claim should not be presented as confirmed.
Public litigation connected with the 2025 breach was consolidated under In re Columbia University Data Breach Litigation.
By August 2026, court records indicated that the parties had reached an agreement in principle and were working toward final settlement terms.
The reviewed record did not establish a confirmed $250 million data-breach settlement.
Therefore, as of September 3, 2026:
A settlement in principle had been reported, but the final approved settlement amount should not be stated as confirmed without a subsequent court filing establishing it.
The Cyberattack and Columbia's Federal Funding Dispute Were Separate Issues
Columbia was already under considerable federal scrutiny when the breach occurred.
That political context sometimes caused two separate stories to become mixed together.
Columbia reached a major agreement with the U.S. government in July 2025 involving federal civil-rights investigations and previously affected federal funding.
That agreement was not a settlement compensating victims of the Columbia data breach.
The federal dispute and the cyberattack occurred during the same politically intense period, but they should be treated as separate legal and institutional matters.
Political Context Without Treating Attacker Claims as Facts
The attack happened during intense political debate around Columbia and U.S. higher education.
The attacker reportedly claimed that the intrusion was intended to examine university admissions information following the Supreme Court's decisions restricting race-conscious college admissions.
That provides context for the attacker's claimed motivation.
It does not prove the attacker's allegations about Columbia's admissions practices.
Stolen documents and an attacker's interpretation of those records are not equivalent to findings from a regulator or court.
That distinction becomes particularly important when cybersecurity incidents overlap with politically controversial issues.
What Universities Can Learn From the Columbia Breach
The Columbia University data breach highlights several defensive priorities.
Control Internet-Facing Systems
The regulatory disclosure identified a publicly exposed system as the initial access point.
Universities need an accurate inventory of internet-facing systems and a process for continuously identifying, patching, restricting, or retiring unnecessary exposure.
Reduce Unnecessary Data Retention
Columbia's later notifications show why institutions need to understand information received through historical services and third parties.
Sensitive information should not remain indefinitely simply because removing it is inconvenient.
Apply Least Privilege
One compromised endpoint or identity should not automatically provide access to unrelated administrative systems and datasets.
Permissions should reflect what users and systems genuinely need.
Improve Detection Visibility
Security teams need endpoint, identity, network, cloud, and authentication telemetry capable of showing what an attacker touched.
Without useful logs, organizations may know that an intrusion occurred without being able to confidently establish its scope.
Prepare for Recovery Before an Incident
Academic services can be operationally critical.
Universities should document:
- Who declares a cyber incident
- How systems are isolated
- How evidence is preserved
- Which systems recover first
- How users are notified
- How compromised identities are handled
- How legal and regulatory teams become involved
A structured incident readiness, response, and recovery program can help organizations establish those responsibilities before an actual emergency.
Why Digital Forensics Matters After a University Breach
A cyber incident does not end simply because systems begin working again.
Investigators need to establish:
- The initial access point
- When unauthorized access began
- What accounts were used
- Which systems were accessed
- What information was removed
- Whether persistence was established
- Whether credentials need to be reset
- Whether other endpoints were affected
That is where a structured digital forensic investigation becomes important.
Forensics can also matter when a security incident leads to litigation, regulatory investigations, or insurance claims because evidence may need to be preserved and analyzed carefully.

Why Antivirus Alone is Not Enough
A university infrastructure consists of much more than student laptops.
It may include:
- Servers
- Virtual infrastructure
- Identity platforms
- Staff endpoints
- SaaS applications
- Cloud environments
- Research systems
- Administrative databases
- Remote-access infrastructure
The security objective is therefore not simply detecting one malicious file.
Defenders need to identify suspicious behavior, isolate compromised assets, investigate related activity, and understand what an attacker could reach.
A managed endpoint security protection program can support broader endpoint visibility, monitoring, detection, investigation, and containment.
A Practical Higher-Education Risk Model
The lesson from Columbia is not simply that universities can be hacked.
The more useful question is what allows an intrusion into one exposed system to become an institutional incident.
Universities can think about four boundaries:
Internet → System
What services are publicly exposed?
System → Identity
What identities and privileges can the compromised system reach?
Identity → Data
What information can those accounts access?
Compromise → Response
How quickly can defenders detect, contain, investigate, and recover?
Weakness across all four layers creates room for an attacker to expand.
Strong controls at later stages can still reduce the damage even when the initial compromise cannot be prevented.
That is the practical meaning of cyber resilience.

Frequently Asked Questions
How many people were affected by the Columbia University data breach?
An August 2025 regulatory filing initially reported 868,969 affected individuals. Columbia later identified additional people and completed further notifications in 2026. Its latest public update did not provide a definitive replacement total.
Was information belonging to 2.5 million people stolen?
Early coverage referred to approximately 2.5 million application records.
That should not automatically be interpreted as 2.5 million confirmed individual victims.
Records and unique individuals are different measurements.
When did the Columbia University breach begin?
The regulatory notification says unauthorized network access occurred on or about May 16, 2025.
The major university IT disruption became visible on June 24, 2025.
How did the attacker get into Columbia?
Official regulatory disclosures identify a publicly exposed system as the initial access route.
Detailed public technical information about the exact vulnerability or exploit remains limited.
What information was exposed?
Depending on the individual, exposed information included Social Security numbers, dates of birth, contact information, demographic details, academic history, admissions information, financial-aid information, insurance information, and certain health-related data.
Were Columbia University medical-center patient records compromised?
Columbia says it has no indication that CUIMC patient records were affected.
Has Columbia found identity theft caused by the breach?
Columbia has stated that it has no evidence of identity theft or fraud resulting from the incident to date.
Did Columbia pay a $250 million data-breach settlement?
A $250 million data-breach settlement was not established by the records reviewed for this update.
By August 2026, the parties had reportedly reached an agreement in principle, but final settlement terms still required completion and court review.
Did Columbia fully implement Zero Trust after the breach?
Columbia reported enhanced security controls and additional safeguards.
Reliable public evidence reviewed for this article does not establish that the university completed a full institution-wide Zero Trust migration because of the breach.
Final Takeaway
The Columbia University data breach matters for more than its size.
It demonstrates how unauthorized access through a publicly exposed system can turn into both an operational disruption and a serious privacy incident inside a major university.
It also demonstrates why early cyberattack numbers must be handled carefully.
The widely repeated 2.5 million figure referred to application-related records in early reporting, while an initial regulatory notification reported 868,969 affected individuals.
Additional people were later identified, but Columbia's latest public information did not establish a final revised total.
The 2026 picture is clearer in other areas.
Notifications have been completed. Columbia continues to provide identity-protection assistance to eligible individuals. Litigation arising from the breach had reached an agreement in principle by August 2026, although a final settlement amount should not be treated as confirmed without later court approval.
For universities and other large institutions, the lesson is practical:
Know every internet-facing asset.
Minimize unnecessary sensitive-data retention.
Restrict identity privileges.
Monitor endpoints and accounts.
Preserve forensic evidence.
Build incident-response procedures before an outage turns into a major breach





