2 min read

Harvard University reports data breach following voice phishing incident

harvard university logo

Harvard says an attacker gained access to Alumni Affairs and Development systems using a phone-based phishing technique.

 

What happened

Harvard University disclosed that an unauthorized party accessed information systems used by Alumni Affairs and Development after a voice phishing attack on November 18, 2025. According to reporting by BleepingComputer, the compromised systems stored contact details and engagement records for students, alumni, donors, staff, and faculty.

 

Going deeper

The university said the intrusion allowed the attacker to view information such as email addresses, telephone numbers, home and business addresses, donation history, and event participation records. Harvard confirmed that the affected systems did not store Social Security numbers, passwords, financial account data, or payment card information. Notifications were issued on November 22 to individuals whose information may have been viewed, and the institution is working with federal authorities and external cybersecurity specialists to assess the scope of the incident. Early findings suggest that multiple groups may be affected, including alumni, donors, parents of students, some current students, and some staff members.

 

What was said

Harvard’s Chief Information Officer and the Vice President for Alumni Affairs and Development said the university removed the unauthorized access immediately after detection and began a review of activity within the affected systems. The notification letters advised recipients to stay alert for communications that appear to come from Harvard but request sensitive information. University representatives stated that they could not yet provide an estimate of the number of individuals affected. BleepingComputer previously reported that Harvard had also been listed on a ransomware leak site in October during a separate incident under investigation.

 

The big picture

Voice phishing has become a more frequent technique in attacks that target higher-education institutions. A 2024 analysis by Google Cloud’s Threat Intelligence team reported a sharp increase in phishing activity directed at US universities, noting that attackers increasingly blend phone-based social engineering with email lures to obtain credentials and circumvent authentication steps. The report found that adversaries often rely on institutional terminology, caller-ID spoofing, and support-style scripts to appear legitimate, making it easier to request access changes or guide victims toward attacker-controlled login portals.

 

FAQs

Why are alumni and donor databases frequent targets?

Large development databases include long-term contact histories, engagement profiles, and sometimes internal notes, which can support social engineering and profiling activities.

 

How does voice phishing differ from email-based attacks?

Voice phishing relies on real-time interaction, where attackers impersonate internal staff or vendors and pressure the victim to share credentials or approve actions during the call.

 

What steps can universities take to reduce the risk of vishing?

Training that covers verification procedures, caller authentication, escalation paths, and rules about never providing credentials by phone helps reduce exposure.

 

Why would attackers target event or donation records?

Engagement records help build convincing impersonation scripts, enabling attackers to reference real events, donation amounts, or past interactions to gain trust.

 

What should individuals do if they receive suspicious university-related messages?

Verify any request through a known official channel, avoid responding directly to unexpected communications, and report unusual activity to the institution’s security office.

Orlando Family Physicians logo

447,000 patients' PHI exposed after phishing attack on Florida practice

Orlando Family Physicians (OFP), a Florida practice with several offices, is the latest health system victimized by a phishing email. Over 447,000...

Read More
digital concept of quantum computing

What is quantum computing and how does it affect cybersecurity?

Quantum computing uses the principles of quantum mechanics, which is a part of physics that explains how very small things like atoms and photons...

Read More
Digital network diagram with laptop, email, security, and connectivity icons

Hot Springs Health Program sends unencrypted email

1,984 patients had their protected health information (PHI) potentially exposed when an unencrypted email was sent by Hot Springs Health Program...

Read More

Subscribe to Paubox Weekly

Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.