Data leak

BleepingComputer

πŸ“… 2024-12-09 🏒 Monroe University IT systems
Primary Source β†—

Incident Details

Monroe University, a New York-based for-profit university, suffered a cyberattack between December 9 and December 23, 2024, in which threat actors exfiltrated data on 320,973 individuals β€” including students, staff, and associated individuals. The breach was not discovered until September 30, 2025, a gap of nine months. Data stolen included names, dates of birth, Social Security numbers, passport numbers, driver’s license numbers, government IDs, medical details, health insurance information, student records, passwords, and financial account details. The responsible group was not publicly named. Monroe University (formerly Monroe College) had previously suffered a ransomware attack in 2019 where attackers demanded 170 bitcoin.

Technical Details

Initial Attack Vector
CWE-284: Improper Access Control
Vendor / Product
Monroe University IT systems

Timeline

  1. 2024-12-09 Breach occurred
  2. 2025-09-30 Publicly disclosed
  3. 2026-01-01 Customers notified