Dartmouth College

Dartmouth College

Dartmouth College, an Ivy League research university, suffered a data breach in August 2025 after hackers exploited a zero-day vulnerability in its Oracle E-Business Suite software. The breach, attributed to the Clop (Cl0p) ransomware gang, compromised sensitive personal and financial data—including names, Social Security numbers, and financial account information—of over **35,000 individuals**, primarily affecting residents of New Hampshire (31,742 victims). While Dartmouth has not confirmed whether a ransom was paid, Clop publicly claimed responsibility on its leak site in November 2025, aligning with its pattern of data extortion rather than encryption. The attack targeted a widely used enterprise system, leveraging the same Oracle vulnerability exploited in prior breaches at institutions like Harvard, Canon, and Mazda. Dartmouth offered affected individuals free identity theft protection via Experian, acknowledging the severe risk of fraud and identity theft. The incident marks one of the largest ransomware attacks on a U.S. educational institution in 2025, underscoring vulnerabilities in higher education cybersecurity and the escalating threat posed by ransomware groups exploiting zero-day flaws.

Source: https://www.comparitech.com/news/dartmouth-notifies-35000-people-of-data-breach-that-leaked-ssns-financial-info/

Dartmouth College cybersecurity rating report: https://www.rankiteo.com/company/dartmouth-college

"id": "DAR1195211112625",
"linkid": "dartmouth-college",
"type": "Ransomware",
"date": "8/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '35,000+ individuals (31,742 in '
                                              'New Hampshire)',
                        'industry': 'Higher Education',
                        'location': 'New Hampshire, USA',
                        'name': 'Dartmouth College',
                        'size': '~6,700 students, ~4,000 employees',
                        'type': 'Educational Institution (Private Ivy League '
                                'University)'},
                       {'customers_affected': '31,742 residents',
                        'industry': 'Public Sector',
                        'location': 'New Hampshire, USA',
                        'name': 'State of New Hampshire (Residents)',
                        'type': 'Government (State)'},
                       {'industry': 'Public Sector',
                        'location': 'Maine, USA',
                        'name': 'State of Maine',
                        'type': 'Government (State)'},
                       {'industry': 'Public Sector',
                        'location': 'Texas, USA',
                        'name': 'State of Texas',
                        'type': 'Government (State)'}],
 'attack_vector': 'Exploitation of zero-day vulnerability in Oracle E-Business '
                  'Suite',
 'customer_advisories': 'Free identity theft protection offered via Experian '
                        '(enrollment deadline: 2026-02-28)',
 'data_breach': {'data_exfiltration': 'Yes (files taken between 2025-08-09 and '
                                      '2025-08-12)',
                 'number_of_records_exposed': '35,000+',
                 'personally_identifiable_information': ['Names',
                                                         'Social Security '
                                                         'numbers'],
                 'sensitivity_of_data': 'High (SSNs, financial account info)',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information (PII)',
                                              'Financial Data']},
 'date_detected': '2025-08-09',
 'date_publicly_disclosed': '2025-11-11',
 'description': 'Dartmouth College confirmed a data breach in August 2025 that '
                'compromised names, Social Security numbers, and financial '
                'account information of over 35,000 individuals. The breach '
                'was attributed to the exploitation of a zero-day '
                'vulnerability in Oracle E-Business Suite software by the Clop '
                'ransomware gang. The incident was publicly disclosed in '
                'November 2025, with New Hampshire accounting for the majority '
                'of victims (31,742). Dartmouth offered free identity theft '
                'protection to affected individuals through Experian.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'breach of sensitive data',
            'data_compromised': ['Names',
                                 'Social Security numbers',
                                 'Financial account information'],
            'identity_theft_risk': 'High (SSNs and financial data compromised)',
            'payment_information_risk': 'High (financial account information '
                                        'exposed)',
            'systems_affected': ['Oracle E-Business Suite']},
 'initial_access_broker': {'entry_point': 'Zero-day vulnerability in Oracle '
                                          'E-Business Suite',
                           'high_value_targets': ['Financial data',
                                                  'PII (SSNs)']},
 'investigation_status': 'Completed (as of public disclosure)',
 'motivation': 'Financial gain (data extortion)',
 'post_incident_analysis': {'root_causes': 'Exploitation of unpatched zero-day '
                                           'vulnerability in Oracle E-Business '
                                           'Suite'},
 'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'Clop (Cl0p)'},
 'references': [{'source': 'Comparitech'},
                {'source': 'Dartmouth College Breach Notice'},
                {'date_accessed': '2025-11-11',
                 'source': 'Clop Ransomware Gang Data Leak Site'}],
 'regulatory_compliance': {'regulatory_notifications': ['State Attorneys '
                                                        'General of Maine, New '
                                                        'Hampshire, and Texas '
                                                        'notified']},
 'response': {'communication_strategy': 'Public notice to victims, media '
                                        'statements, free identity theft '
                                        'protection enrollment (deadline: '
                                        '2026-02-28)',
              'incident_response_plan_activated': 'Yes (investigation '
                                                  'completed)',
              'third_party_assistance': ['Experian (identity theft '
                                         'protection)']},
 'stakeholder_advisories': 'Public notice to 35,000+ affected individuals, '
                           'media statements',
 'threat_actor': 'Clop (Cl0p) ransomware gang',
 'title': 'Dartmouth College Data Breach (August 2025)',
 'type': ['Data Breach', 'Ransomware Attack'],
 'vulnerability_exploited': 'Zero-day vulnerability in Oracle E-Business Suite'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.