What happened
Harvard University disclosed that its Alumni Affairs and Development systems were accessed by an unauthorised party following a phone-based phishing attack discovered on 18 November 2025. Exposed information included email addresses, telephone numbers, home and business addresses, event attendance records, donation details and biographical data for alumni, donors, parents, some students and some staff. Harvard said Social Security numbers, passwords and payment card data were not involved.
How the deception worked
The attacker telephoned someone with access to the advancement systems and, over the call, obtained what was needed to log in as that person. Harvard characterised the incident explicitly as a phone-based phishing attack on its Alumni Affairs and Development environment. Advancement offices are attractive because a small number of staff hold broad read access to donor records, and because fundraising work involves frequent legitimate calls from unfamiliar people, which normalises an unexpected voice asking for help. Once authenticated as the employee, the intruder queried and exported donor and alumni records before the university revoked the access and brought in outside responders.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant MFA on advancement systems and a standing rule that credentials or one-time codes are never handled over the phone would have blocked the login.
Sources (2)
- Harvard University discloses data breach affecting alumni, donorsBleepingComputer·bleepingcomputer.comOpen ↗
- Harvard University reports data breach following voice phishing incidentPaubox·paubox.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.