
St. Louis, Missouri-based Saint Louis University said that the cyber security incident it suffered last year compromised the sensitive personal information of more than 90,000 individuals.
Founded in 1818, Saint Louis University (SLU) is a private Jesuit research university with campuses in St. Louis, Missouri, and Madrid. The University presently enrolls more than 15,000 students across 94 undergraduate majors and 88 graduate disciplines and has more than 2,000 academic and 6,000 administrative staff in its ranks.
In a recent data security incident notice filed with the Office of the Maine Attorney General, the University said that in March last year, it identified suspicious activity in its internal network and initiated an internal investigation, with assistance from third party cyber security experts, to determine the nature and scope of the incident.
SLU’s investigation later revealed that malicious actors infiltrated its network between December 2022 and July 2023 and accessed personal information belonging to thousands of individuals.
“As a result of our investigation, we confirmed that certain email accounts containing your personal information were accessed at various times from December 2022 through July 2023,” SLU said.
“The forensic investigation confirmed the unauthorised activity was limited to those email accounts and a limited number of documents stored in SLU’s SharePoint and OneDrive platforms. In other words, the incident did not involve any other systems or data.”
On April 24, SLU concluded that the sensitive personal data stored in the compromised email accounts contained names, other personal identifiers and Social Security Numbers. The filing with the Maine state regulator also revealed that at least 93,612 individuals were affected by the data breach.
“In addition to the actions described above, we are taking steps to reduce the risk of this type of incident occurring in the future, including reviewing our technical security measures,” SLU added.
While SLU did not find any evidence of the compromised data being misused, the possibility for the same cannot be ruled out. It has urged all affected individuals to remain vigilant, review their credit reports and financial statements on a regular basis, and report suspicious transactions to relevant law enforcement authorities.
The university is also offering one year of complimentary credit monitoring and identity theft protection services through Experian IdentityWorks to all the individuals affected by the data security incident.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543