Skip to Content, Navigation, or Footer.
Support independent student journalism. Support independent student journalism. Support independent student journalism.
The Dartmouth
September 28, 2026
The Dartmouth

College reaches $750,000 settlement following data breach affecting 96,000 members of the Dartmouth community

Affected individuals may be eligible for a cash payment of $75 or, if they choose to go through an additional review process, up to $5,000 for losses related to the breach.

092726-dregonzales-oracle.png

A Sept. 21 motion for final approval filed in the United States District Court for the Western District of Texas ordered Dartmouth to pay $750,000 in a class action lawsuit filed against the College over an August 2025 nationwide data breach of Oracle E-Business Suite, which Dartmouth uses to manage accounting, expense reporting, payroll, human resources management, inventory catalog, paying vendors and procurement cards. The plaintiffs alleged that the College failed to protect the personal information, including Social Security numbers and bank account numbers, of more than 96,000 people.

Russian ransomware group Clop claimed responsibility for the attack on its website, located on the dark web, where the stolen data associated with multiple victims were posted.

Of the 33 class action plaintiffs who originally filed with a national suit in March 2026, The Dartmouth identified two who were connected to Dartmouth: Matthew Ross ’15 and Lisa Mabey, a former Dartmouth Hitchcock Medical Center patient.

Members of the settlement class, defined as individuals whose data was accessed by Clop in the breach, may be eligible for one of two payment options by submitting a claim form. Option A allows a class member to receive up to $5,000 by submitting “documentation for losses related to the data incident,” while option B offers the class members a payment of $75 without providing any documentation, according to the settlement website.

Claims must be submitted online or by mail by Oct. 21. Affected individuals are also eligible to receive two years of credit monitoring, according to a copy of the settlement notice reviewed by The Dartmouth.

In a Sept. 14 email statement to The Dartmouth, College spokesperson Jana Barnello wrote that the College “has now agreed on settlement terms in connection with class action litigation filed against Oracle, Dartmouth and a number of entities whose data was potentially accessed as a result of this incident.”

“Individuals whose data was potentially affected received a court-approved notice from the Settlement Administrator, which will include how they may be able to participate,” Barnello wrote. 

Barnello added that the College “continues to closely monitor our vendors’ data security practices.” 

The case was settled “without any admission by Dartmouth of liability or wrongdoing, with respect to all released claims of the releasing parties,” the agreement reads. “Dartmouth does not in any way acknowledge, admit to, or concede any of the allegations made in the Complaint, and expressly disclaims and denies any fault or liability, or any charges of wrongdoing.” 

This data breach was the result of a zero-day exploit of Oracle’s EBS platform. A zero-day attack is when a hacker takes advantage of an unknown weakness in computer software, hardware or firmware.

Dartmouth computer science professor Sami Saydjari, who specializes in cybersecurity engineering, said zero-day attacks “have been increasing rapidly over the last five years.” 

Zero-day attacks are “inevitable and they’re now part of the cyber ecosystem,” Saydjari said. “That means that the people that use these pieces of software, like Dartmouth and many other institutions … they have to anticipate that these kinds of zero-days are going to happen.” 

Saydjari said that it is “not okay” for institutions whose vendors are breached to refuse to accept part of the blame for zero-day attacks because it is the “joint responsibility of the vendor, like Oracle, and the users of that software, such as Dartmouth” to protect “sensitive data.”

“There are many countermeasures that consumers of these software like Dartmouth can do to mitigate the risks,” he said. “They can have an architecture that will make it harder for adversaries to exploit it. They can have better detection techniques to see when it’s been exploited.” 

Saydjari added that “the lesson learned” for institutions should be that they “have to proactively assume that zero-days are going to happen.” 

Zero-days are “inevitable. They’re going to be increasingly happening,” Saydjari said. “[Institutions and vendors] have to invest in architecture, security architectures, mechanisms that help mitigate, prevent, detect and respond as quickly as possible to minimize damage. That is their duty.”

A final approval hearing for the settlement has been scheduled for Nov. 5, at 10 a.m. ET.

Oracle Corporation and Dartmouth Information, Technology and Consulting did not respond to requests for comment. The lawyers representing the plaintiff and the lawyer representing the College did not reply to requests for comment.


Eliza Dorton

Eliza Dorton '29 is a reporter from Washington, D.C. and is studying English and public policy. Outside the classroom, she enjoys reading and going on walks.