
Strategic Education Inc., a Herndon, Virginia-based higher education company that operates Strayer University and Capella University, has disclosed a data breach in which an unauthorized actor accessed the company’s computer servers over a three-day period in late February 2026 and copied files containing highly sensitive personal information. Regulatory filings with attorneys general in five states identify at least 176,043 affected individuals.
The intrusion took place between Feb. 23 and Feb. 25, 2026. The company discovered the breach on May 21, 2026 — nearly three months after it occurred — and began mailing notification letters to affected individuals on May 29, 2026. The breach was reported to attorneys general in multiple states on June 1 and 2, 2026, and was also disclosed to the California Attorney General.
The compromised files contained names, Social Security numbers, driver’s license numbers and passport numbers. The affected individuals included people connected to Strayer University, Capella University or both institutions.
State-level filings show that Texas had the largest share of affected residents, with 100,845 individuals impacted, followed by 63,272 in South Carolina, 8,188 in Massachusetts, 2,673 in Maine and 1,065 in Vermont. The company said it recently concluded its investigation of the incident.
Strategic Education is providing affected individuals with complimentary identity monitoring services through Kroll, a corporate investigations and risk consulting firm. The package includes three components: single-bureau credit monitoring, unlimited fraud consultation and identity theft restoration.
The credit monitoring service sends alerts when changes appear on a person’s credit file, such as a new credit application made in their name. Recipients who do not recognize flagged activity can contact a Kroll fraud specialist to assess whether it signals identity theft.
The fraud consultation component gives affected individuals access to Kroll specialists who can explain their legal rights and protections, assist with placing fraud alerts and help investigate suspicious activity that may be linked to identity theft.
If an affected individual becomes a victim of identity theft, a dedicated Kroll licensed investigator will be assigned to assess the full scope of the theft and work to resolve related issues on that person’s behalf.
Individuals can enroll by visiting Kroll’s enrollment website and entering the membership number included in their notification letter. Enrollment must be completed before the activation deadline stated in the letter. Enrolling will not affect a person’s credit score, the company said. To be eligible for credit monitoring, individuals must be at least 18 years old, have established credit in the United States, have a Social Security number in their name and have a U.S. residential address associated with their credit file.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543