Data leak
BleepingComputer
Primary Source βIncident Details
Monroe University, a New York-based for-profit university, suffered a cyberattack between December 9 and December 23, 2024, in which threat actors exfiltrated data on 320,973 individuals β including students, staff, and associated individuals. The breach was not discovered until September 30, 2025, a gap of nine months. Data stolen included names, dates of birth, Social Security numbers, passport numbers, driver’s license numbers, government IDs, medical details, health insurance information, student records, passwords, and financial account details. The responsible group was not publicly named. Monroe University (formerly Monroe College) had previously suffered a ransomware attack in 2019 where attackers demanded 170 bitcoin.
Technical Details
- Initial Attack Vector
- CWE-284: Improper Access Control
- Vendor / Product
- Monroe University IT systems
Timeline
- 2024-12-09 Breach occurred
- 2025-09-30 Publicly disclosed
- 2026-01-01 Customers notified