Baker University in Kansas disclosed a significant data breach after detecting suspicious activity and a network outage in December 2024. An investigation revealed that attackers had unauthorized access to the university’s systems between December 2 and December 19, 2024, resulting in the theft of sensitive documents containing personal, health, and financial information of 53,624 individuals. The compromised data included names, dates of birth, Social Security numbers, driver’s license numbers, financial account details, health insurance and medical information, passport numbers, student identification numbers, and tax identification numbers. The university has stated there is no evidence so far that the stolen information has been used for fraudulent activities.
In response to the breach, Baker University has offered free credit monitoring services to affected individuals and has notified state and federal regulators. The university worked with external cybersecurity experts to investigate the incident, rebuild compromised platforms, and implement additional security measures to prevent future incidents. The nature of the attack and the identity of the perpetrators have not been disclosed, and there is no public evidence of extortion or ransom demands related to the breach. The university continues to encourage those affected to monitor their accounts and credit reports for suspicious activity.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Baker University publicly disclosed that a December 2024 breach affected more than 53,000 individuals. The university said it notified affected people and regulators and offered complimentary credit monitoring.
In December 2024, the university discovered the incident after a network outage and began securing systems and investigating the breach. It also engaged external cybersecurity experts and started rebuilding compromised systems.
Baker University said unauthorized actors accessed its network between December 2 and December 19, 2024. During this period, sensitive personal, financial, and medical information was exposed.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.