Columbia University’s massive 2025 data breach affected 868,969 people, including thousands who received alarming notification letters despite having zero connection to the prestigious institution.
The Breach That Revealed Invisible Relationships
Between May and June 2025, a politically motivated attacker infiltrated Columbia’s systems and exfiltrated 460 gigabytes of sensitive data. The haul included Social Security numbers, dates of birth, financial aid records, and academic histories stretching back decades.
The hacker, claiming to expose post-affirmative action admissions practices, managed to steal information on over 2.5 million applicants and up to 1.8 million SSNs. Columbia detected the breach in late June but didn’t notify the public until July, leaving many victims scrambling to understand how their most sensitive identifier ended up in a stranger’s hands.
How Your Data Ended Up in Columbia’s Vaults
Your confusion about receiving a Columbia breach letter makes perfect sense—the university collected your SSN through recruitment pipelines you probably forgot existed. Before 2012, Columbia routinely ingested prospect data from testing organizations like College Board and ACT, plus various scholarship services that shared SSNs as student identifiers.
According to Columbia officials:
“We believe that this information came to the University through student recruitment services that historically provided this type of information to colleges and universities from prospective students who indicated they wanted to share it, whether to report a test score or to request further information about specific colleges, universities, or scholarship programs.”
The Broader Data Retention Problem
Electronic Frontier Foundation technologists describe Columbia’s decades-long SSN retention as “really indicting,” highlighting how institutions treat personal data as assets rather than liabilities. This isn’t Columbia’s unique failing—it’s symptomatic of an entire sector that hoarded sensitive identifiers long past their usefulness.
Protecting Yourself from Invisible Data Relationships
Your compromised SSN won’t expire like a credit card. Place credit freezes with all three bureaus, monitor accounts aggressively, and consider that this breach might be the first of many surprise notifications.
The uncomfortable truth? Your data probably lives in systems you can’t imagine, collected through forgotten interactions decades ago. Columbia’s breach illuminates a chilling reality: you’re vulnerable to tracking users through institutions you never chose to trust.
Update 6/5/2026: Article was updated to include Columbia’s statement and a link to Columbia’s statement as well as correcting a factual inaccuracy that it affected millions.




























