University of St. Thomas-Houston Data Breach Affects 26k

Published
March 9, 2026
Updated
June 11, 2026
University of St. Thomas-Houston Data Breach Affects 26k
University of St. Thomas

University of St. Thomas-Houston, a private Catholic university in Houston, Texas, disclosed a data breach that affected 26,644 individuals across multiple states, including 24,158 Texas residents.

Filings show that three Maine residents, six Vermont residents, six New Hampshire residents and 48 Massachusetts residents were affected. The university began notifying consumers on May 26, 2026, through U.S. mail, publication in print media and its website.

According to the university's notification to consumers, the university became aware of suspicious activity within its network on or about Aug. 12, 2025. An investigation determined that an unauthorized actor had access to certain systems within the university's environment between July 25, 2025, and Aug. 12, 2025. During that period, certain files were accessed and potentially acquired by the unauthorized actor.

A ransomware group known as INC Ransom claimed responsibility for the attack. On Aug. 21, 2025, the group posted on its dark web portal, accessible through the Tor network, claiming to have obtained 1.8 terabytes of the university's data. The group also shared sample screenshots of the stolen information on its portal.

After the incident was detected, the university conducted what it described as a "thorough and time-intensive review" of the affected files to determine what information they contained and to whom the information related, according to the notification. That review was recently completed, and consumer notifications followed.

The types of personal information that may have been exposed include names, addresses, Social Security numbers, dates of birth, driver's license numbers, state identification card numbers, other government-issued identification numbers (such as passport numbers), financial account information and security questions and answers. The breach also potentially exposed protected health information, including medical information and health insurance information.

According to the university's notification, approximately eight Rhode Island residents may also have been affected by the incident.

University of St. Thomas-Houston's response to the breach

The university is offering affected individuals 12 months of free credit monitoring and identity theft protection services through Experian IdentityWorks. The enrollment deadline is Aug. 31, 2026.

Identity restoration support is available to affected individuals, even without enrolling in the credit monitoring program. Experian agents can help investigate and resolve fraud incidents, including assisting with disputing charges, closing accounts and placing credit freezes, according to the notification.

For questions or concerns, affected individuals can call the university's dedicated assistance line at 1-866-736-9716, available from 9:00 a.m. to 9:00 p.m. Eastern Time, excluding major U.S. holidays. Individuals may also write to the university at 3800 Montrose Blvd., Houston, TX 77006.

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
May 26, 2026
Date of Breach
July 25, 2025
Breach Discovered Date
March 24, 2026
Total People Affected
26644
Information Types Exposed
  • Name of individual
  • Address
  • Social Security Number Information
  • Driver’s License number
  • Government-issued ID number (e.g. passport, Social Security number, credit or debit card number)
  • Medical Information
  • Health Insurance Information
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image