What happened
Princeton University disclosed in November 2025 that an attacker gained access to a database used by its advancement office after a targeted phishing attack against a university employee. Names, addresses, phone numbers, email addresses and donation-related information for alumni, donors, students, parents, faculty and staff were exposed. Princeton said Social Security numbers, passwords and financial account details were not stored in the affected database. Class-action suits followed.
How the deception worked
The intrusion started with a targeted phishing approach aimed at a single staff member with advancement-system access rather than a mass campaign. The message and follow-up were crafted around university fundraising work, an area where staff routinely receive unfamiliar outreach about events, gifts and alumni records, which made the approach unremarkable. The trust signal abused was the appearance of legitimate internal or alumni-related correspondence; the pressure was ordinary work urgency rather than threats. Once the employee's session or credentials were captured, the attacker authenticated as them and queried the advancement database directly, exporting constituent records before the university detected the activity and cut off access.
The control that would have caught it· our reading, not a claim from the sources
Hardware-backed or passkey MFA for advancement staff, plus alerting on unusual bulk queries against constituent databases, would have contained the single compromised account.
Sources (2)
- Princeton Database Breached in Targeted Phishing IncidentPrinceton Alumni Weekly·paw.princeton.eduOpen ↗
- Cybersecurity incident information and FAQPrinceton University OIT·oit.princeton.eduOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.