Dartmouth College Data Breach Notice (Oregon Attorney General)
If you received a notice from Dartmouth College, here’s what the filing says was exposed, and what to do about it.
Dartmouth College notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on November 24, 2025. The filing puts the incident itself on August 09, 2025.
The personal information of 98,990 people was exposed in a data breach at Dartmouth College. The incident occurred on August 09, 2025, and the college filed its notification with Oregon authorities on November 24, 2025 — an interval of 107 days, or roughly three and a half months.
What This Exposure Actually Means for Those Affected
If you received a notification from Dartmouth College, your personal information was included in this incident. The filing lists personal information as the category exposed. No passwords, no financial account numbers, and no permanent government identifiers such as Social Security numbers were named in the record.
That absence is important. Because no passwords were exposed, there is no need to change any Dartmouth College password, and the account itself does not appear to be at direct risk of takeover from this incident. The exposed data consists of the kind of personal details that, once released, cannot be taken back. They retain long-term value to identity thieves who may attempt to use them for fraud, account takeover attempts elsewhere, or impersonation schemes that develop over months or years.
The 107-Day Gap Between Incident and Notification
The record shows the breach took place on August 09, 2025 and the filing occurred on November 24, 2025. That 107-day period is the most concrete fact this notification provides. Notification timelines vary by state law and by when an organisation completes its investigation, so the filing does not establish whether the delay was unusual. It simply states both dates, and readers can weigh that interval for themselves.
How to Determine Whether You Were Included
Dartmouth College is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not part of the group of 98,990 people whose records were exposed. However, letters are sent to the last known address. Anyone who has moved since August 09, 2025 should contact Dartmouth College directly to confirm whether their information was involved.
What the Exposed Personal Information Enables
Personal information alone can still be valuable to criminals. Thieves often combine it with data obtained from other sources to build convincing profiles for synthetic identity fraud, tax refund fraud, or medical identity theft. Because the filing does not list Social Security numbers or financial details, the immediate risk of new account fraud opened solely with this data is lower than in breaches that expose those stronger identifiers. Yet the information remains useful for targeted phishing, impersonation, or as a building block in larger identity theft attempts that may surface later.
The record does not disclose the root cause, whether the data was exfiltrated, or the precise fields included beyond the broad category of personal information. Those details remain unknown to the public.
The Limits of What This Filing Tells Us
This notification establishes three clear facts: the date of the incident, the date it was filed with Oregon authorities, and that personal information belonging to 98,990 people was exposed. It does not describe how the breach occurred, how long any unauthorised access lasted, or whether any specific security controls succeeded or failed. Those questions fall outside what this type of filing contains.
Speculation about the college’s security posture or comparisons to other incidents would go beyond the record. The only information available is what the filing itself states.
Practical Steps That Address This Specific Exposure
- Monitor your mail for a letter from Dartmouth College. This remains the most reliable way to confirm whether your records were included.
- Place a fraud alert with the three major credit bureaus. A fraud alert makes it harder for someone to open new accounts in your name using any personal details that may have been exposed.
- Review your Explanation of Benefits statements from health insurers. Watch for claims you did not receive care for, as personal information can sometimes be used in medical identity schemes.
- Be wary of unsolicited contact that references Dartmouth College or uses any personal details the letter may have listed. Treat such outreach as suspicious even if it appears legitimate.
- Consider freezing your credit if you rarely open new accounts. A credit freeze stops new credit applications cold and can be lifted when needed.
The exposure cannot be undone, but its practical impact depends on what you do next. The letter from Dartmouth College is the starting point. Once you know the exact details that applied to you, the steps above can limit how that information might be used against you in the months and years ahead.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
Trailer Transit Inc Listed by metaencryptor Ransomware Group
Nationwide power-only transport services with 40+ years of experience. Trust Trailer Transit for dep…