Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Breach - Harvard, Dartmouth Confirm Data Breaches
Data Breach Attacks Latest News News & Analysis Phishing Threats and Vulnerabilities Zero Day

Harvard, Dartmouth Confirm Data Breaches

Kirsten DoyleBy Kirsten DoyleNovember 26, 2025Updated:November 26, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Harvard Dartmouth Data Breaches
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Harvard University has disclosed a vishing attack that exposed the personal information of students, parents, alumni (and some of their spouses, partners), donors, staff, and faculty members.   

Exposed data includes “biographical information pertaining to University fundraising and alumni engagement activities” as well as emails, phone numbers, home and business addresses, attendance records, and donation details.  
  

The University said it acted immediately to remove the actor’s access to its systems and prevent further unauthorized access. “Our investigation is currently ongoing. We are working with third-party cybersecurity experts and law enforcement to investigate this incident. This website will be updated.” 

Harvard said it is working with third-party cybersecurity experts and law enforcement to investigate this incident.  

In a statement, it said: “Though the information systems that were accessed do not generally contain Social Security numbers, passwords, payment card information, or financial account numbers, they do include personal information such as email addresses, telephone numbers, home and business addresses, event attendance,  details of donations to the University, and other biographical information pertaining to University fundraising and alumni engagement activities.” 

Be Alert For Unusual Communications 

As the investigation continues, Harvard said will assess if specific notifications are needed.  

“We encourage you to be on alert for any unusual communications that purport to come from the University, particularly those asking for sensitive information,” it added, advising people to:  

  • Pause before you engage. Be especially cautious with unexpected calls, text messages, or emails requesting sensitive information or asking you to reset your password, even if they appear to come from colleagues or trusted partners. 
  • Verify unusual requests. If something seems off, do not use the contact information provided in the message or call. Verify the request through a trusted source before responding.  

In a separate incident in October, Harvard confirmed that it was a victim of a data breach after the Clop ransomware gang added it to its data-leak extortion site, claiming it had breached the school’s systems using the zero-day vulnerability in Oracle’s E-Business Suite servers.   

This ransomware actor has been exploiting the zero-day flaw (CVE-2025-61882) since early August 2025 to steal sensitive files from many victims’ Oracle EBS platforms, targeting The Washington Post, Logitech, GlobalLogic, and American Airlines subsidiary Envoy Air, with their data also leaked online and now available for download via Torrent. 

Dartmouth College also found itself in the crosshairs of this gang, and also disclosed a data breach following the Clop gang’s data leak, which stole the personal information of 1,494 individuals. However, the total number impacted by this breach is expected to be much higher, as the school has not yet filed breach notices with other states.  

Through the investigation, Dartmouth determined that an unauthorized actor took certain files between 9 and 12 August 2025. “We reviewed the files and on 30 October 2025, identified one or more that contained your name and Social Security number,” the college says in letters mailed to individuals affected by the data leak.” 

Dartmouth said that the malefactors also stole documents containing the financial account information of impacted individuals.  

These Databases Are Goldmines 

Michael Bell, Founder & CEO of Suzu Labs, said: “What’s striking about the Harvard and Dartmouth breaches is that two completely different attack vectors (vishing and Oracle EBS zero-day exploitation) successfully targeted the same type of data at similar institutions within weeks, demonstrating that alumni and donor databases are being systematically targeted through multiple methods simultaneously. These databases are gold mines: they contain high-net-worth individuals’ contact information, giving history that reveals financial capacity, and relationship networks enabling sophisticated social engineering and fraud.” 

According to him, organizations with donor databases need to assume they’re under attack from multiple vectors at once and implement both technical controls (patching legacy systems like Oracle EBS) and human-layer defenses (security awareness training for development staff handling sensitive donor relationships). 

The Convergence of Risks 

John Carberry, Security Sleuth, at Xcape Inc, added that these two events underscore the complex and multifaceted threats facing universities that hold valuable data.  

“Harvard fell victim to a voice phishing attack, which compromised its Alumni Affairs systems and exposed contact and donation information, a low-tech method that yielded high-value financial espionage.  Dartmouth, in contrast, was targeted by the Cl0p ransomware gang, who exploited a zero-day vulnerability (CVE-2025-61882) in the Oracle E-Business Suite to steal sensitive files containing Social Security numbers and financial data.” 

Carberry said: “These events highlight the convergence of risks: identity compromise through phone calls or social engineering and ERP integrations that make business systems vulnerable. To mitigate these risks, universities should implement phishing-resistant MFA, strong SSO, rigorous help-desk verification processes, strict least-privilege access controls for advancement and ERP connectors and monitor for unusual API usage or bulk data exports – along with rapid token and key rotation after any suspected breach.” 

He said donors and alumni should anticipate targeted fraud and phishing attempts and should consider credit freezes for added security.  “When a phone call or an integration can unlock your donor vault, identity, not just endpoints, is the new campus perimeter.”  

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

May 19, 20262 Mins Read

Canvas cyberattack disrupts universities as ShinyHunters threatens massive data leak

May 12, 20267 Mins Read

Zara Owner Inditex Confirms Customer Data Breach Affecting Nearly 200,000 People

May 11, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}