
A lawsuit has been filed against the University of Minnesota for failing to protect the sensitive personal information of staff and students and for waiting for over a month prior to notifying affected parties about a data breach incident.Earlier this month, the University of Minnesota confirmed that it suffered a severe data breach incident that affected countless alumni and staff and compromised personal data records dating back to the eighties.The University’s confirmation arrived more than a month after a threat actor on 20th July claimed they infiltrated the University’s systems and stole personal data including 7 million unique Social Security Numbers.Immediately after learning about the data security incident, the University launched an investigation to understand the scope of the same and learned on 21st July that it had suffered a breach of alumni records. “The preliminary assessment is that the data at issue is from 2021 and earlier,” University spokesperson Jake RIcker told CBS News.“Our investigation is continuing, but our security professionals have not detected any system malware (including ‘ransomware’), encrypted files or fraudulent emails related to the incident. There have been no known disruptions to current University operations as a result of this data security incident,” he added.A lawsuit has been filed against the University of Minnesota on behalf of a former student and former employee, accusing the University of not taking enough steps to protect personal information. According to the Minneapolis Star Tribune, attorneys for the plaintiffs claimed that the University “was fully capable of preventing” the data security incident and that the University violated the Minnesota Government Data Practices Act.While the University did not comment on the lawsuit filed against it, Ricker told the media that it took steps since 2021 to bolster its cybersecurity defences."Alongside experts, the University has taken steps since 2021 to bolster its overall system security through actions such as enhancing multi-factor authentication capabilities and increasing the frequency of monitoring activities," he said.The institution is yet to comment on how the threat actors infiltrated its systems, but according to the Cyber Express, “the hacker claimed to have exploited Computer Niggy Exploitation (CNE) to access the university’s data warehouse, containing records digitised since 1989. This database system stored valuable and sensitive information about students, faculty, and staff.”"The safety and privacy of all members of the University community are among the University’s top priorities. The University investigates these situations immediately and fully, and will keep the community informed as additional, relevant information becomes available," Ricker added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543