Columbia University Information (Dental) Listed by Global Secret Group Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Columbia University Information (Dental) appears on a list published by the Global Secret Group ransomware group on August 14, 2026, indicating that personal data may have been exposed. Individuals who received services from the unit are urged to review any communications from the university and monitor their accounts for unusual activity.
A ransomware group known as Global Secret Group has listed Columbia University Information (Dental) on its leak site, with the listing dated August 14, 2026. That claim has not been publicly confirmed by the university as of writing. For patients, students, staff, and others who may have dealt with Columbia’s dental-related services, the practical question is straightforward: if any personal or clinical information were ever copied and posted, what would that mean and what should people do next.
Public detail is limited. The listing does not establish that a breach occurred, does not confirm who was affected, and does not inventory what—if anything—was taken. It is an extortion-style accusation on a criminal site. Readers should treat it as unverified until the organisation or an official authority says otherwise.
Inside the listing
According to the listing, Global Secret Group has named Columbia University Information (Dental) and associated the entry with New York, US, the website columbia.edu, the colleges and universities sector, reported revenue of $6.6 billion, and an employee range of 20,000–25,000. The same listing claims “Properties: 296 GB (283,387 Files, 11,268 Folders).”
The number of people affected is unknown. Data types named as exposed are not disclosed. Method of access, timing of any alleged intrusion, and whether any files were actually published are not established in the material provided. The university has not publicly confirmed the incident as of writing. A leak-site entry of this kind is a pressure tactic: groups post a victim name, sometimes a volume claim, and threaten release unless demands are met. Volume figures and file counts on such pages are attacker assertions, not audited inventories.
Who is Global Secret Group?
Global Secret Group is known publicly as a ransomware and extortion actor that operates in the familiar double-extortion pattern used by many crews: encrypt systems where they can, exfiltrate data where they claim to have done so, and list organisations on a leak site to force payment. Like peer groups, it relies on public naming, countdowns or staged releases, and marketing-style descriptions of stolen “properties” to amplify fear.
Well-documented public reporting on such groups generally describes opportunistic targeting across sectors, use of affiliate-style or brand-name leak sites, and claims that should be independently verified. None of that background proves that this specific listing is accurate. For this victim name, the only concrete claim in the facts is that the group has listed Columbia University Information (Dental) and attached the country, website, revenue, industry, employee range, and the 296 GB / file-and-folder figures above. Anything beyond that about this incident remains the group’s unverified assertion.
About Columbia University Information (Dental)
Columbia University is a major U.S. research university based in New York. Dental schools and dental clinical operations within large universities typically combine education, research, and patient care. They sit at the intersection of student records, employee data, and healthcare-related information.
A listing that ties a dental-related university unit to a ransomware leak site matters because people who seek dental care or study or work in that environment often share identifiers, contact details, insurance or billing data, and clinical history with the institution. Even when a claim is unconfirmed, the sensitivity of that sector is why such listings draw attention. The listing itself does not prove that any of those categories were copied or published.
What data was at risk
The facts state that data types named as exposed are not disclosed. It is therefore not possible to say from the public listing material what fields or file categories were involved—if any transfer occurred at all.
If files from a university dental context were ever taken, organisations in this sector typically hold some mix of patient scheduling and clinical notes, insurance and billing records, student and trainee information, employee records, and routine administrative documents. That is sector context, not a description of this listing’s contents. Exact contents here remain unconfirmed; the group’s file-count and volume claims are not a substitute for a verified disclosure from the university or a regulator.
What's at stake
For individuals, the stakes are conditional. If personal or clinical information related to them were ever exposed, risks could include phishing and social-engineering attempts that reference real appointments or bills, account-takeover tries using reused passwords or known email addresses, and longer-term fraud concerns where identifiers and insurance details are involved. Medical and dental information is sensitive because it can be used to build convincing scams or to pressure people privately. None of that means any specific person’s data is in this alleged set.
For the organisation, an unconfirmed leak-site listing still creates reputational pressure, operational distraction, and the need to investigate and communicate carefully. A listing does not, by itself, establish negligence, security failures, or the success of an attack. It establishes only that a criminal group chose to name the institution and attach marketing-style metrics.
In concrete terms, people weighing this news may want to keep the following in mind:
- The listing is an accusation by Global Secret Group, not a claimed breach notice from Columbia University.
- People affected, if any, are unknown; data types are not disclosed in the facts provided.
- Claimed volume (296 GB, 283,387 files, 11,268 folders) comes from the attackers’ page and is unverified.
- If your information were involved, typical risks would center on targeted scams, identity misuse, and misuse of health- or billing-related details—not automatic public exposure of every record.
- Official confirmation, scope, and guidance—if they come—would come from the university or appropriate authorities, not from the leak site.
Steps worth taking either way
Until there is a confirmed notice that names affected populations and data categories, treat the situation as unresolved. If you have been a patient, student, or employee connected to Columbia dental services, watch for unexpected messages that urge urgent payment, credential entry, or transfer of funds, especially if they claim to reference a “breach” or “dental records.” Prefer contact channels you already trust rather than links or numbers in unsolicited email or text.
If you use the same password on multiple sites, change it on important accounts and enable multi-factor authentication where available. If you later receive an official notification that financial or insurance identifiers were involved, follow that notice’s instructions on credit monitoring or fraud alerts. These steps are prudent whether or not this particular listing proves accurate.
You can also run a free exposure scan of your email to check whether your address has already appeared in other known breach datasets—useful baseline hygiene, not proof about this claim. Stay with primary sources: statements from the university and, if applicable, regulators. A ransomware group’s listing is a claim; your response should stay calm, conditional, and grounded in what is actually confirmed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Coggins Insurance Agency Listed by Global Secret Group Ransomware GroupPro-Tuff | Decals Listed by Global Secret Group Ransomware GroupCook Remodeling Listed by Global Secret Group Ransomware GroupMacofin Hellas S.A. Listed by Global Secret Group Ransomware GroupLatest breaches
Publicly posted by global-secret-group — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.