DataBreachSearch.com

Did Columbia University have a data breach?

Answer

Yes. Columbia University reported a data breach to the Texas Attorney General on May 20, 2026.

What the filing says

Reported to
Texas Attorney General
Filing date
May 20, 2026
Breach date
May 16, 2025
People affected
Not stated in the filing

In plain terms

Columbia University filed a data breach notice with the Texas Attorney General on May 20, 2026. This report confirms that unauthorized access to internal systems occurred, potentially exposing personal information. Individuals who received a notification letter should review their accounts for suspicious activity.

Columbia University formally reported a data security incident to the Texas Attorney General on May 20, 2026. The breach event itself is listed as occurring on May 16, 2025.

The university's public filing indicates that personal information may have been compromised due to unauthorized parties accessing internal systems. The specific categories of data involved were not detailed in the public record. An investigation into the full scope of the incident is currently underway.

If you received a data breach notification letter from Columbia University, it means your personal data was likely affected. These letters are sent to inform individuals about the incident and guide them on steps to protect themselves.

To safeguard your information, it is advisable to closely monitor your financial accounts and credit reports for any unusual activity. Consider changing passwords for online accounts, especially if you use similar credentials across multiple services. Be cautious of unsolicited communications, such as emails or texts, that request personal details.

This information is derived from the official data breach filing made public with the Texas Attorney General's office.

Other filings by Columbia University

Companies often file the same breach in several states. Each filing is listed separately.

Commonly recommended next steps

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Look up another company

Other breaches reported in Texas

DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with Columbia University.