Dartmouth College Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
Dartmouth College disclosed a data breach on November 24, 2025, that occurred on August 09, 2025 and affected 98,990 individuals. Anyone who received a notice or believes their information may have been exposed should review the details and consider protective steps such as monitoring accounts and placing fraud alerts.
Nearly 99,000 people may have had personal information exposed in a data incident at Dartmouth College, according to a notice filed with Oregon authorities. For anyone who has studied at, worked for, applied to, or otherwise dealt with the college, the practical question is straightforward: whether their details were among those involved, and what that could mean for identity and account security in ordinary life.
Public reporting ties the incident itself to August 9, 2025, with Dartmouth’s notification to Oregon residents reflected in a filing dated November 24, 2025. Exact technical details remain limited in the disclosure, but the scale alone makes the event consequential for a large group of individuals.
Inside the incident
According to the breach notice associated with the Oregon Attorney General’s reporting channel, Dartmouth College notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on November 24, 2025. That filing places the incident on August 9, 2025. The number of people affected is reported as 98,990. The notice describes the exposed material as personal information, without a fuller public itemization in the summary available here.
How the incident was discovered, what systems were involved, whether data was exfiltrated or only accessed, and whether any specific method or actor was identified are not detailed in the facts provided. Timing between the August incident date and the November filing is a matter of public record in the notice; reasons for that interval are not explained in the available summary. No dollar figures, file names, or technical forensic findings are included in the disclosed facts.
How a breach like this happens
In general terms, incidents that lead colleges and universities to issue personal-information notices often begin with unauthorized access to accounts, servers, or cloud services that store student, alumni, employee, or applicant records. Common pathways in the higher-education sector include compromised credentials (for example through phishing or reused passwords), exploitation of unpatched software, misconfigured remote access, or third-party vendor systems that hold institutional data. Once inside an environment, an attacker may move laterally, search for databases or document stores, and copy or encrypt information.
None of those patterns is confirmed for this specific Dartmouth matter. No threat group is named in the facts, and inventing one would be inappropriate. What is typical across the sector is that organizations later notify regulators and affected people when they determine that personal information was involved, sometimes weeks or months after the initial event while investigation and mailing lists are completed. Defensive lessons that institutions commonly emphasize afterward include stronger multi-factor authentication, tighter vendor oversight, network segmentation around sensitive records, and faster detection of unusual data access—again as general practice, not as findings about this case.
About Dartmouth College
Dartmouth College is a long-established private institution of higher education in the United States, part of the Ivy League, with undergraduate and graduate programs and a wide community of students, faculty, staff, alumni, and applicants. Like peer colleges and universities, it routinely maintains records needed for admissions, enrollment, financial aid, employment, research administration, fundraising, and alumni relations.
A breach affecting nearly six figures of individuals is consequential in this sector because higher-education data stores often link academic identity to contact details, identifiers, and other personal attributes that can be reused for fraud or social engineering. The institution’s reputation for stewardship of community data, and the trust of people who share information as a condition of study or work, are also at stake whenever a notice of this kind is filed—even when public technical detail remains thin.
The information in question
The breach notification, as summarized in the available facts, names the exposed data as personal information. It does not provide a public line-item list of fields in the material used for this account. Therefore the exact contents remain unconfirmed beyond that broad category.
Organizations of this kind typically hold, in ordinary operations, items such as names, addresses, email addresses, phone numbers, dates of birth, student or employee identifiers, and sometimes more sensitive elements depending on the system (for example financial-aid or HR-related data). Those are sector norms, not a confirmed inventory of what was involved here. Readers should treat any claim about specific fields as unverified unless Dartmouth or a regulator publishes a clearer breakdown.
The real-world impact
For affected individuals, the concrete risks center on misuse of personal information: targeted phishing that references a real college relationship, attempts to open accounts or reset passwords, or identity-related fraud if enough identifiers were present. Even when a notice only says “personal information,” people often face months of heightened vigilance because they cannot see exactly what an unauthorized party obtained.
For the college, impacts typically include investigation and notification costs, possible regulatory follow-up, support burden for help desks and alumni or student services, and longer-term questions from the community about data protection. None of those outcomes is quantified in the facts for this incident, and no finding of fault is established in the disclosure summary. The reported figure of 98,990 people simply indicates that the potential human footprint is large.
If your data was in this breach
If you have a past or present connection to Dartmouth and believe you may be among those notified, start with the official notice if you received one: it should explain what the college believes was involved and any support it is offering. Place fraud alerts or credit freezes with the major credit bureaus if you are concerned about identity theft; monitor bank, credit card, and email accounts for unexpected activity; and treat unsolicited messages that claim to be from the college or about “your breach refund” or “account verification” with skepticism. Change passwords on important accounts, especially if you reused a Dartmouth-related password elsewhere, and enable multi-factor authentication where available.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets circulating outside this single incident. Keep records of any official letters and of steps you take. Public detail on this event remains limited to the Oregon filing date, the August 9, 2025 incident date, the affected-person count, and the broad label of personal information; further clarity, if it comes, will need to come from the college or regulators rather than from speculation.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.