Yale University Sued Over 2008 Data Breach

Yale University Sued Over 2008 Data Breach

In a letter to those affected by the 2008 data breach, Yale said the breach was discovered on June 16, 2018, during a security review of its servers. After the university discovered the breach, it notified those affected and offered credit monitoring services and identity theft prevention tips.

Two lawsuits have been filed in federal court against Yale University. Both lawsuits are claiming damages from a 2008 data breach at Yale, which was discovered earlier this year.

Between April 2008 and January 2009, intruders gained access to a Yale database and gathered names, Social Security numbers, dates of birth, email addresses, and in some cases, physical addresses.

In a letter to those affected by the data breach, Yale said the breach was discovered on June 16, 2018, during a security review of its servers. After the university discovered the breach, it notified those affected and offered credit monitoring services and identity theft prevention tips.

A class-action lawsuit filed this week on behalf of Andrew Mason of Virginia claims that Yale was negligent in its handling of student data and that the university was reckless and acted with “willful misconduct” as it “turned a blind eye to” possibilities of a prior data breach. It also claims that the university used unfair trade practices.

A federal lawsuit on behalf of Julie Mason of New York was filed in August. The lawsuit also claims negligence, willful misconduct, recklessness and unfair trade practices. In addition, it claims that Yale had still not notified everyone who was affected as of Aug. 1, six weeks after discovering the data breach.

The breach affected an estimated 119,000 Yale alumni, faculty and staff, according to the lawsuits. One of the lawsuits claims that the breach affected a far broader group of people than initially identified by Yale, and that Yale did not make people aware that this type of their personal data had been stored.

In its letter to those affected, Yale said that the university had deleted personal information from the affected database in 2011 as part of a data protection program, but had not detected the data breach at that time.

“Yale takes seriously the protection of personal information, and we continue to improve our electronic security and eliminate the unnecessary storage of such information,” the university’s statement to those affected read. “We very much regret this incident and the inconvenience to you.”

About the Author

Jessica Davis is the Associate Content Editor for 1105 Media.

Featured

  • Report: 47 Percent of Security Service Providers Are Not Yet Using AI or Automation Tools

    Trackforce, a provider of security workforce management platforms, today announced the launch of its 2025 Physical Security Operations Benchmark Report, an industry-first study that benchmarks both private security service providers and corporate security teams side by side. Based on a survey of over 300 security professionals across the globe, the report provides a comprehensive look at the state of physical security operations. Read Now

    • Guard Services
  • Identity Governance at the Crossroads of Complexity and Scale

    Modern enterprises are grappling with an increasing number of identities, both human and machine, across an ever-growing number of systems. They must also deal with increased operational demands, including faster onboarding, more scalable models, and tighter security enforcement. Navigating these ever-growing challenges with speed and accuracy requires a new approach to identity governance that is built for the future enterprise. Read Now

  • Eagle Eye Networks Launches AI Camera Gun Detection

    Eagle Eye Networks, a provider of cloud video surveillance, recently introduced Eagle Eye Gun Detection, a new layer of protection for schools and businesses that works with existing security cameras and infrastructure. Eagle Eye Networks is the first to build gun detection into its platform. Read Now

  • Report: AI is Supercharging Old-School Cybercriminal Tactics

    AI isn’t just transforming how we work. It’s reshaping how cybercriminals attack, with threat actors exploiting AI to mass produce malicious code loaders, steal browser credentials and accelerate cloud attacks, according to a new report from Elastic. Read Now

  • Pragmatism, Productivity, and the Push for Accountability in 2025-2026

    Every year, the security industry debates whether artificial intelligence is a disruption, an enabler, or a distraction. By 2025, that conversation matured, where AI became a working dimension in physical identity and access management (PIAM) programs. Observations from 2025 highlight this turning point in AI’s role in access control and define how security leaders are being distinguished based on how they apply it. Read Now

New Products

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.