Columbia University disclosed a data breach that exposed Social Security numbers and other personal data, including records belonging to people who said they had no direct relationship with the school. Reporting found Columbia had retained legacy applicant and recruitment data from before 2012, when universities received student information from scholarship, recruitment, and testing sources; some affected individuals learned their SSNs were stored by Columbia despite never attending or applying. The incident has drawn scrutiny over long-term retention of sensitive data and the university’s notification process, with some breach notices reportedly sent to outdated family addresses because current contact details were unavailable.
The disclosure also raised questions about how student data was historically shared across the admissions ecosystem. Columbia said the exposed records appear tied to older datasets, while the College Board said its Student Search program would not have provided SSNs to Columbia and that, before ending SSN sharing in 2018, the relevant scenario would have been students sending SAT scores to the university; ACT likewise no longer uses SSNs as student identifiers. Separately, Santa Clara University confirmed a breach affecting 2,206 records, underscoring continued exposure risks across higher education institutions handling sensitive student and applicant information.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Following a Columbia University data breach, some recipients reported their Social Security numbers were exposed even though they had no direct relationship with the school. The article says delayed notifications drew criticism, with some notices reportedly sent to parents' addresses because current contact information was hard to locate.
Ars Technica confirmed that ACT no longer uses Social Security numbers as student identifiers, and that the practice ended roughly a decade earlier.
Columbia University said that before 2012 it received prospective student data, including Social Security numbers, from multiple recruitment, scholarship, and testing sources. The university indicated this legacy data appears to have remained in its databases.
The College Board said it ended sharing Social Security numbers in 2018. It also disputed that its Student Search opt-in program would have provided a student's SSN to Columbia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.