CSIDB logo
Incident

Nelnet Servicing

Incident posture

Attack window
Jun 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-18 00:00

Linked entities

Victim
Nelnet Servicing
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity breach at Nelnet Servicing exposed sensitive personal data of approximately 2.5 million student loan borrowers through compromised systems used by loan servicers OSLA and EdFinancial. Unauthorized actors exploited a vulnerability to access registration information—including names, addresses, email addresses, phone numbers, and Social Security Numbers—over an extended period before detection, though no financial account details were compromised. The incident heightened risks of identity theft and phishing targeting affected individuals, prompting investigations into potential legal action and the provision of complimentary identity protection services for impacted borrowers.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Nelnet Servicing breach occurred between June 2022 and July 22, 2022, when unauthorized actors infiltrated the systems of the technology services provider supporting student loan management for the Oklahoma Student Loan Authority (OSLA) and EdFinancial. Attackers exploited an unspecified vulnerability to compromise Nelnet's network, maintaining access for approximately six weeks before being detected and blocked by the company. On August 17, 2022, an investigation confirmed that sensitive registration data from student loan accounts had potentially been accessed during the intrusion. The breach impacted 2,501,324 individuals whose loan servicing was managed through Nelnet's web portal platform. Exposed information included full names, physical addresses, email addresses, phone numbers, and Social Security Numbers, though Nelnet confirmed no financial account numbers or payment details were accessed.

OSLA and EdFinancial initiated notifications to affected customers following the completion of the investigation, coordinating with state authorities including the Maine Attorney General's office. Both organizations clarified that only borrowers whose accounts were hosted by Nelnet Servicing were affected, with EdFinancial noting a subset of its client base relied on alternative infrastructure. Impacted individuals received guidance on enrolling in 24-month complimentary identity theft protection services provided through Experian. The exposure of highly sensitive identifiers prompted concerns over heightened risks of phishing campaigns, social engineering attempts, and impersonation scams targeting student loan borrowers. Markovits, Stock & DeMarco law firm announced an investigation into potential class action litigation in response to the incident, citing the severity of the exposed personal data. Nelnet did not publicly disclose technical details regarding the initial attack vector or specific containment measures beyond confirming the breach termination date.

Sources

Sources available to members: 1 source.

CSIDB