Skip to content
Back to Blog
low severity November 24, 2025 · 4 min read

Dartmouth College Data Breach Notice (Oregon Attorney General)

If you received a notice from Dartmouth College, here’s what the filing says was exposed, and what to do about it.

Dartmouth College notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on November 24, 2025. The filing puts the incident itself on August 09, 2025.

Dartmouth College Data Breach Notice (Oregon Attorney General)

The personal information of 98,990 people was exposed in a data breach at Dartmouth College. The incident occurred on August 09, 2025, and the college filed its notification with Oregon authorities on November 24, 2025 — an interval of 107 days, or roughly three and a half months.

What This Exposure Actually Means for Those Affected

If you received a notification from Dartmouth College, your personal information was included in this incident. The filing lists personal information as the category exposed. No passwords, no financial account numbers, and no permanent government identifiers such as Social Security numbers were named in the record.

That absence is important. Because no passwords were exposed, there is no need to change any Dartmouth College password, and the account itself does not appear to be at direct risk of takeover from this incident. The exposed data consists of the kind of personal details that, once released, cannot be taken back. They retain long-term value to identity thieves who may attempt to use them for fraud, account takeover attempts elsewhere, or impersonation schemes that develop over months or years.

The 107-Day Gap Between Incident and Notification

The record shows the breach took place on August 09, 2025 and the filing occurred on November 24, 2025. That 107-day period is the most concrete fact this notification provides. Notification timelines vary by state law and by when an organisation completes its investigation, so the filing does not establish whether the delay was unusual. It simply states both dates, and readers can weigh that interval for themselves.

How to Determine Whether You Were Included

Dartmouth College is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not part of the group of 98,990 people whose records were exposed. However, letters are sent to the last known address. Anyone who has moved since August 09, 2025 should contact Dartmouth College directly to confirm whether their information was involved.

What the Exposed Personal Information Enables

Personal information alone can still be valuable to criminals. Thieves often combine it with data obtained from other sources to build convincing profiles for synthetic identity fraud, tax refund fraud, or medical identity theft. Because the filing does not list Social Security numbers or financial details, the immediate risk of new account fraud opened solely with this data is lower than in breaches that expose those stronger identifiers. Yet the information remains useful for targeted phishing, impersonation, or as a building block in larger identity theft attempts that may surface later.

The record does not disclose the root cause, whether the data was exfiltrated, or the precise fields included beyond the broad category of personal information. Those details remain unknown to the public.

The Limits of What This Filing Tells Us

This notification establishes three clear facts: the date of the incident, the date it was filed with Oregon authorities, and that personal information belonging to 98,990 people was exposed. It does not describe how the breach occurred, how long any unauthorised access lasted, or whether any specific security controls succeeded or failed. Those questions fall outside what this type of filing contains.

Speculation about the college’s security posture or comparisons to other incidents would go beyond the record. The only information available is what the filing itself states.

Practical Steps That Address This Specific Exposure

  • Monitor your mail for a letter from Dartmouth College. This remains the most reliable way to confirm whether your records were included.
  • Place a fraud alert with the three major credit bureaus. A fraud alert makes it harder for someone to open new accounts in your name using any personal details that may have been exposed.
  • Review your Explanation of Benefits statements from health insurers. Watch for claims you did not receive care for, as personal information can sometimes be used in medical identity schemes.
  • Be wary of unsolicited contact that references Dartmouth College or uses any personal details the letter may have listed. Treat such outreach as suspicious even if it appears legitimate.
  • Consider freezing your credit if you rarely open new accounts. A credit freeze stops new credit applications cold and can be lifted when needed.

The exposure cannot be undone, but its practical impact depends on what you do next. The letter from Dartmouth College is the starting point. Once you know the exact details that applied to you, the steps above can limit how that information might be used against you in the months and years ahead.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed November 24, 2025
Last reviewed July 22, 2026
Affected 98990
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email