People search Indiana University data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 10 Indiana University-linked incidents, with headline counts up to 650K+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Indiana University breach history matters
Indiana University operates in Technology. Across indexed rows, recurring themes include mixed intrusion and disclosure events. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2018 — — Indiana University: Information on this security breach is provided by…
Cataloged incident. Information on this security breach is provided by the Office of the Indiana Attorney General Exposed categories include Personal information. BreachHistory cites approximately 1 affected records in this row. See the indiana-university2018 and canonical BreachHistory entry.
2017 — — Indiana University: Location of breached information: Improper Disposal…
Cataloged incident. Location of breached information: Improper Disposal Business associate present: No Exposed categories include Personal information. BreachHistory cites approximately 1K+ affected records in this row. See the indiana-university2017 and canonical BreachHistory entry.
2016 — — Indiana University: Indiana University Health Arnett Hospital notified…
Cataloged incident. Indiana University Health Arnett Hospital notified patients of a data breach when the hospital became aware of a missing unencrypted flash drive from their emergency department. The information compromised included patient information from emergency department visits, names, dates of birth, ages, home telephone numbers, medical record numbers, dates of service, diagnoses and treating physicians. More information: http://www.beckershospitalreview.com/healthcare-information-technology/f... Exposed categories include Personal information. No attested victim count is published for this row yet. See the indiana-university2016 and canonical BreachHistory entry.
2014 — — Indiana University: Indiana University announced that the personal data…
Cataloged incident. Indiana University announced that the personal data of 146,000 students and graduates was breached. The information included their Social Security numbers and addresses and may have affected students and graduates from 2011 to 2014 at seven of its campuses. According to the university The information was not downloaded by an authorized individual looking for specific sensitive data, but rather was accessed by three automated computer data-mining applications, called webcrawlers, used to improve Exposed categories include Personal information. BreachHistory cites approximately 146K+ affected records in this row. See the indiana-university2014 and canonical BreachHistory entry.
2014 — — Indiana University: Students who attended the university between 2011…
Cataloged incident. Students who attended the university between 2011 and 2014 may have had their data exposed after it was stored on an unprotected site. The data was accessed by three webcrawlers but there is not evidence it was accessed by any unauthorized individuals. BreachHistory cites approximately 146K+ affected records in this row. See the indiana-universityu and canonical BreachHistory entry.
2013 — — Indiana University: Data breach reported, 150K records
Cataloged incident. Data breach reported. Reference: http://news.iu.edu/releases/iu/2014/02/data-exposure-disclosure.shtml BreachHistory cites approximately 150K+ affected records in this row. See the indiana-university2013 and canonical BreachHistory entry.
2012 — — Indiana University: A security breach caused the personal information…
Cataloged incident. A security breach caused the personal information of 650,000 President's Challenge participants nationwide to be exposed. Hackers may have accessed participant names, email addresses, dates of birth, and nutritional data. People throughout Indiana University were participating in a Health IU fitness inter-campus competition. No financial information was available to the hacker or hackers. A small percentage and unknown number of Social Security numbers may have been available through other o Exposed categories include Personal information. BreachHistory cites approximately 650K+ affected records in this row. See the indiana-university2012 and canonical BreachHistory entry.
2011 — — Indiana University: Health information stored on a computer server was…
Cataloged incident. Health information stored on a computer server was accidentally made available to the public online between August and September of 2011. Patients who were seen by a former faculty member of the school were affected because of a configuration error that occurred on August 12. The issue was discovered on September 9 and had been corrected by September 10. Patients seen by a certain doctor between January of 2007 and June of 2011 at clinics in Carmel and Indianapolis, Indiana were affected. So Exposed categories include Personal information. BreachHistory cites approximately 757 affected records in this row. See the indiana-university2011 and canonical BreachHistory entry.
2006 — — Indiana University: The computer housing the reservations data base was…
Cataloged incident. The computer housing the reservations data base was compromised. Data included credit card account numbers and names. Exposed categories include Personal information. No attested victim count is published for this row yet. See the indiana-university2006 and canonical BreachHistory entry.
2005 — — Indiana University: A hacker may have accessed the names, Social…
Cataloged incident. A hacker may have accessed the names, Social Security numbers and grades of students who enrolled in Introduction to Business courses between 2001 and 2005. The computer may have been hacked and installed with malware as early as August. A representative believes the breach occurred because the files were stored on a computer that did not have current anti-virus and system-protection software. Exposed categories include Personal information. BreachHistory cites approximately 5K+ affected records in this row. See the indiana-university2005 and canonical BreachHistory entry.
Patterns and analysis
- Mixed intrusion and disclosure events — appears across multiple Indiana University catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Review OAuth app permissions and revoke unused third-party integrations.
- Step 5: Bookmark the Indiana University company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/indiana-university · Latest: indiana-university2018.
Sources: BreachHistory catalog (10 rows for Indiana University), company and regulator disclosures cited in individual breach records.