Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yale University disclosed in 2018 that intruders had accessed a university database between April 2008 and January 2009, exposing information associated with approximately 119,000 people. Yale said it discovered the intrusion on June 16, 2018, during a review of university servers—nearly a decade after the access occurred.

What happened in the Yale data breach?

According to Yale’s July 27, 2018 notice to Washington Attorney General Robert W. Ferguson, intruders gained electronic access to a university database from April 2008 through January 2009 and extracted personal information. Yale reported approximately 119,000 people affected nationwide, including 1,742 Washington residents.

“We have no indication that the data taken between April 2008 and January 2009 was misused,” Harold Rose, Yale’s senior vice-president and associate general counsel, wrote in the notice. That describes Yale’s assessment when it reported the incident; it does not establish that misuse never occurred.

When did Yale discover the breach?

Yale said it discovered the older intrusion on June 16, 2018, while reviewing university servers. The gap between the access and discovery is why the incident was described as a decade-old breach. It was not a decade of known, ongoing access: Yale placed the intrusion between April 2008 and January 2009.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yale also said it had deleted personal information from the affected database in September 2011 as part of its data-protection program. That deletion did not reveal the earlier intrusion.

What information was exposed?

Yale reported that names and Social Security numbers were extracted. Dates of birth were involved in nearly all cases, Yale email addresses in many cases, and physical addresses in some cases. The database did not contain financial information, according to the university’s notice.

A separate intrusion affected 33 people

The same 2018 review uncovered a different intrusion of the same server, involving names and Social Security numbers of 33 people. Yale’s separate notice dates discovery of that incident to June 11, 2018, and places the access sometime between March 2016 and June 2018. It was distinct from the 2008–09 breach; the 33 people should not be added to the approximately 119,000 affected by the older incident. Yale’s separate notice about the 33-person incident gives those details.

What did Yale do after discovering the breach?

In its 2018 notification, Yale said it mailed letters to affected Washington residents, offered them 12 months of identity monitoring at no cost through Kroll, and notified the major consumer reporting agencies. The Kroll offer was part of that historical response; the notice does not establish that it remains available.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yale said approximately 3% of affected people nationwide lacked verified current addresses and that it published notice information for them. The university also described continuing a data-loss-prevention program to identify and remove unnecessary personal information and test servers for vulnerabilities.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should potentially affected people do?

Yale’s 2018 notice advised affected people to review account statements and credit reports, and to consider a fraud alert or a security freeze. These are recommendations from the historical notice, not confirmation that anyone’s information was misused. Anyone who received Yale’s notification should follow its guidance and check accounts and credit files for activity they do not recognize.

For a current university security concern—such as suspected loss or theft of sensitive data—Yale’s Information Security Office incident-reporting page lists a 24/7 urgent reporting number, 203-627-4665, for events affecting university confidentiality, integrity, or availability.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.