← Campbell University

2026 Campbell University — cloud storage intrusion; PHI/PII categories disclosed; count pending (Apr)

2026 Unknown records affected Share on X

Data compromised

Broad PHI/PII categories may include names, addresses, DOB, SSN, driver's licence, passport, medical/treatment/mental-health data, financial and payment card data, and student identifiers; victim count not finalized; HHS notified ≥500 individuals

Technical writeup

Verified university disclosure — incident discovered April 1, 2026. Campbell University in North Carolina reported unauthorized access to one cloud-based data storage platform from March 31 through April 1, 2026, contained to that environment per the school. The investigation remained ongoing into affected individuals and data types; disclosed categories span extensive PHI and PII including medical, mental-health, financial, government ID, and student records. Campbell reported no evidence of misuse at notice time, notified federal law enforcement, and filed with HHS indicating at least 500 individuals' protected health information was involved while the final count remained pending. Separately, the Incransom ransomware group claimed the university on April 11, 2026 and threatened a 500 GB release—an unverified actor claim distinct from the university's confirmed access finding. HIPAA Journal summarized regulatory context June 26, 2026.

Root cause

Unauthorized access to a cloud-based data storage platform March 31–April 1, 2026; isolated to single platform per university

References