Cyber Incident Victim: University of St. Thomas
Timeline
Summary
University of St. Thomas experienced a ransomware attack that disabled its servers and led to the exposure of personal information, including documents related to sexual harassment investigations and confidential settlement agreements, which were later posted on the dark web. A lawsuit filed by a former student and employee alleged inadequate security and delayed notification, resulting in a settlement where the university agreed to provide credit monitoring, identity theft protection, and cash payments ranging from $50 to $4,500 for verified losses, without admitting liability.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 25, 2025, unauthorized access to certain systems at the University of St. Thomas began, according to a later investigation by third‑party specialists. The intrusion continued until August 12, 2025, when the university’s servers went dark as the fall semester approached, preventing students from accessing online resources such as financial aid and course registration. On August 13, 2025, the institution issued a campus‑wide email stating that it had proactively quarantined the affected servers after detecting an unauthorized party attempting to access the system, but at that time it had found no evidence of compromised information. The university said it became aware of the activity on or about August 12, immediately took steps to secure the network, and notified law enforcement. In September 2025, President Sinda Vanderpool announced that specialists were determining the scope of the data impacted and that affected individuals would receive a formal notification after the investigation’s completion, while offering free credit monitoring codes in the interim.

The investigation later concluded that certain files had been accessed or taken during the July 25 to August 12 window. Among the exposed material were documents detailing investigations into student complaints of sexual harassment and misconduct by professors, which named both the students and the accused employees. Also disclosed were confidential settlement and payout agreements between the university and some of its former top‑level leaders, as alleged by the plaintiff. In October 2025, a former student and employee, Amy Crull, filed a lawsuit claiming that the university had failed to safeguard a “treasure trove” of personal information and had not notified the campus community in a timely manner about the breach. The suit further alleged that the university obfuscated the nature of the breach and the threat it posed by refusing to disclose how many people were impacted, how the breach occurred, when it was discovered, or why notification was delayed. Some students and faculty told the Houston Chronicle in October 2025 that they had not been informed about the extent of the breach.
On August 4, 2026, the university announced a settlement to compensate data breach victims, offering credit monitoring and up to $4,500 for extraordinary losses stemming from fraud or identity theft that was more likely than not caused by the breach. The settlement also provides up to $500 for ordinary losses such as attorneys’ or credit repair service fees, costs associated with freezing or unfreezing credit, and credit monitoring costs, or a $100 payment for individuals who can show their personal information was exposed. Claimants may alternatively receive three years of credit monitoring and identity theft protection services with a bureau chosen by the university, including theft protection insurance, or, if they opt not to claim documented out‑of‑pocket losses or credit monitoring, an alternative cash payment of $50. To receive compensation for out‑of‑pocket expenses not previously reimbursed and fairly traceable to the breach, individuals must submit claims by September 28, 2026, providing proof such as official receipts. The settlement is not an admission of liability; the plaintiffs maintain that their claims have merit while the university continues to deny the allegations, stating that it settled to avoid the time and cost of continued litigation. As part of the agreement, Amy Crull is expected to receive a $4,000 service award for representing the class, and the university agreed to pay up to $240,000 for attorneys’ fees. Further information about the claim process is available at the settlement website ustdatasettlement.com.
