University of California Data Breach (2020): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The University of California Data Breach (2020) (reported December 24, 2020) exposed Dates of birth, Education levels, Email addresses and Ethnicities belonging to roughly 547K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
The University of California reported the breach in December 2020. It stemmed from a vulnerability in the systems of a third-party provider, Accellion. The incident resulted in the exposure of records covering 547,000 people, including 547 thousand unique email addresses along with names, dates of birth, genders, ethnicities, and additional academic and employment-related attributes.
Further details on the method of access or the full scope of files involved have not been publicly disclosed beyond the vendor connection. The data was later provided to Have I Been Pwned by researcher Cyril Gorlla.
How a breach like this happens
Incidents involving third-party providers often begin with the exploitation of known or unpatched vulnerabilities in widely used file-transfer or collaboration platforms. Attackers scan for exposed instances of such software and use the access to retrieve stored data without needing to compromise the primary organization’s own networks.
Once initial access is obtained, the attackers can enumerate and exfiltrate files that the vendor hosts on behalf of its clients. The client organization may remain unaware until the vendor detects the intrusion or the data surfaces elsewhere.
About University of California
The University of California operates a large public university system that maintains extensive records on current and former students, faculty, and staff. Such institutions routinely collect and store personal identifiers, academic histories, and contact information to support enrollment, employment, and administrative functions.
A breach at this scale is consequential because the organization serves hundreds of thousands of individuals whose records are retained for years after their direct affiliation ends.
The information in question
The facts name the following data types as exposed: dates of birth, education levels, email addresses, ethnicities, genders, job titles, names, and phone numbers. The incident description also references social security numbers and other academic-related attributes, though the precise combination of fields present in the exfiltrated records has not been independently verified beyond these listings.
Organizations of this type commonly hold additional information such as addresses, student identification numbers, and course enrollment details; whether those fields were included remains unconfirmed.
Why it matters
Compromised dates of birth, names, and contact details can be combined with other publicly available information to support targeted phishing or account takeover attempts. When ethnicities, genders, or academic records are also exposed, the data may be used for profiling or more specific social-engineering campaigns.
For the organization, the incident underscores the downstream effects of vendor security posture on the privacy of its community members, even when internal systems are not directly accessed.
Were you affected?
Individuals who attended or worked at the University of California around the time of the incident can check their email address against public breach notification services. Monitoring credit reports and university communications for any follow-up guidance from the institution provides an additional practical step.
Readers may also run a free exposure scan of their email address through established breach-data lookup tools to determine whether their information appears in known public datasets from this or other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Roblox Developer Conference (2023) Data Breach (2020)Travel Oklahoma Data Breach (2020)Capital Economics Data Breach (2020)Chowbus Data Breach (2020)Latest breaches
Read GalaxyWarden’s full analysis of the University of California Data Breach (2020) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.