• News/
  • https://www.bleepingcomputer.com/news/security/dartmouth-college-confirms-data-breach-after-clop-extortion-attack/

Dartmouth College confirms data breach after Clop extortion attack

BleepingComputer
·
Sergiu Gatlan
·
Published Nov 25, 2025
·
Updated

​Dartmouth College has disclosed a data breach after the Clop extortion gang leaked data allegedly stolen from the school's Oracle E-Business Suite servers on its dark web leak site. The private Ivy League research university, founded in 1769, has an endowment of $9 billion as of June 30, 2025, over 40 academic departments and programs, and more than 4,000 undergraduate students, with a 7:1 undergraduate-to-faculty ratio. In a breach notification letter filed with the office of Maine's Attorney General, Dartmouth says the attackers exploited an Oracle E-Business Suite (EBS) zero-day vulnerability to steal personal information belonging to 1,494 individuals. However, the total number of people potentially impacted by this data breach is likely much larger, given that the school is headquartered in Hanover, New Hampshire, and it hasn't yet filed a breach notice with the state's Attorney General. "Through the investigation, we determined that an unauthorized actor took certain files between August 9, 2025, and August 12, 2025. We reviewed the files and on October 30, 2025, identified one or more that contained your name and Social Security number," the college says in letters mailed to those affected by the data leak. In a separate appendix filed with Maine's AG, Dartmouth added that the threat actors also stole documents containing the financial account information of impacted individuals. A Dartmouth College spokesperson was not immediately available for comment when contacte...

Read full article

Affected Software

1 affected component
Oracle E-Business Suite

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a data breach at Dartmouth College linked to the Clop extortion gang.

2

What security implications are discussed?

The article highlights the risks of data exposure and the potential impact of extortion attacks on educational institutions.

3

What products or software are affected?

The affected software is Oracle E-Business Suite, which was compromised during the attack.

4

Who is responsible for the data breach?

The Clop extortion gang is identified as the group responsible for the attack.

5

What steps has Dartmouth College taken in response to the breach?

Dartmouth College has acknowledged the breach and is likely implementing measures to enhance its security and mitigate risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203