Incident

Harvard University reports a phone phishing attack and data breach on alumni affairs and development systems


Learn More

Harvard University, is reporting a data breach affecting its Alumni Affairs and Development Office after a phone-based phishing attack. The breach was discovered on November 18, 2025, when a hacker gained access to information systems containing sensitive donor and alumni data. 

This is a second cybersecurity incident to impact Harvard in 2025, after the October breach linked to an Oracle E-Business Suite vulnerability. The exposed data includes:

  • Personal contact information
  • Email addresses
  • Telephone numbers
  • Home and business addresses
  • Donation details and records
  • Event attendance records

The number of affected individuals is not disclosed. The breach affected a diverse range of Harvard affiliates, including alumni, their family members, donors, parents of current and former students, as well as some current students and faculty members.

According to Harvard officials, the accessed systems do not generally contain Social Security numbers, passwords, or financial account numbers. Harvard has also not yet determined whether it will send notifications to individual affiliates whose data was compromised.

The university is currently working with third-party cybersecurity experts and law enforcement agencies to investigate the incident.

Harvard University reports a phone phishing attack and data breach on alumni affairs and development systems