HIGH SEVERITYEducation

NYU Data Breach

NYU (New York University) Website Breach (2025): 3.2 Million Alumni & Student Records Exposed by Politically Motivated Hacktivist

Private research university.

Verified by ObscureIQ Intelligence

6.0Severity
3.2MRecords
2Fields
2025Year

ObscureIQ Breach Intelligence Scores
0.0
Breach Risk Index
3
Data Value
0
Market Recency
0
days
Since Breach

Risk Interpretation

High risk of phishing, identity theft, tuition fraud, payroll fraud, and targeting of students, faculty, and alumni. Academic and international-student context can also improve scam credibility.

🎯 Impact & Downstream Threats

On March 22, 2025, NYU's official website was compromised for approximately two hours. The attacker replaced the homepage with a black-background display showing purported admissions data — including charts of SAT and ACT scores and demographic breakdowns — alongside approximately 3.1 million records of applicant and student data. The incident appeared politically motivated rather than financially driven, with the attacker using the defacement to draw attention to admissions practices. NYU resto

Primary downstream threats:
  • Targeted phishing campaigns using exposed email addresses

🔓 Threat Vectors

Phishing, credential stuffing & account takeover
Name-based social engineering

📋 Breach Intelligence

EntityNYU (New York University (NYU))
OrganizationUniversity • USA
Breach Date2025-03-22
Disclosure2025-06-09
DBC Added2025-03-25
Records~3.2M (3,160,701 records)
Attack VectorMisconfiguration
Data SubjectsStudent
Breach PathwayDirect
SourceDataBreach.com / ObscureIQ
SensitivityStandard
CA Reported2025-06-09
Breach ID989.0
StatusConfirmed

📝 Executive Summary

New York University (NYU) suffered a website defacement and data exposure on March 22, 2025, when a hacker identified as "@bestn-gy" on X compromised NYU's official homepage for approximately two hours. The attacker replaced the page with charts purporting to show admissions data broken down by race, alongside a racial epithet. The same hacker has been linked to a similar attack on Columbia University. NYU restored the site and reported the incident to law enforcement, but not before data on roughly 3.1 million applicants and students had been exposed. The breach exposed names and email addresses, with the attacker also claiming access to additional admissions-related records, including test scores and demographic data, drawn from NYU's data warehouse. Even where only names and email addresses are confirmed, that combination is enough to enable targeted phishing campaigns, identity theft, and tuition or financial aid fraud. The academic and international student context associated with NYU makes such scams easier to craft convincingly. NYU sent a university-wide notification approximately six hours after the breach and later characterized data displayed during the defacement as "inaccurate and misleading." No class-action litigation or formal regulatory enforcement action has been publicly documented in connection with this incident. Affected individuals should treat unexpected emails referencing NYU, admissions, or student accounts with caution, and monitor for signs of account takeover or impersonation.

🏢 About NYU

New York University is a major private research university founded in 1831 and headquartered in Greenwich Village, Manhattan. It is one of the largest private universities in the United States by enrollment, with campuses in New York, Abu Dhabi, and Shanghai, along with global academic centers in more than a dozen cities. NYU is particularly strong in law, business, medicine, and the arts and is consistently ranked among the top research universities worldwide.

University | Higher education and research | Academic institution | USA
UniversityUSAnyu.edu

🗂 Why They Hold Your Data

Universities collect identity, contact, academic, financial, employment, applicant, alumni, and research-linked records across education and administrative systems.

📰 Recent Developments

NYU has continued expanding its global academic programs and research enterprise. The university has invested in its medical school and hospital affiliations, as well as technology and innovation initiatives. No major governance or structural changes have been prominently reported in the period surrounding the breach.

🔍 Data Points Exposed

2 verified field types:
Email
Name

Canonical Fields

email_address, full_name

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~3.2M records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: nyu-2025

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of NYU
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

MisconfigurationEducationEmail

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom