2026 Campbell University — cloud storage intrusion; PHI/PII categories disclosed; count pending (Apr)
Data compromised
Broad PHI/PII categories may include names, addresses, DOB, SSN, driver's licence, passport, medical/treatment/mental-health data, financial and payment card data, and student identifiers; victim count not finalized; HHS notified ≥500 individuals
Technical writeup
Verified university disclosure — incident discovered April 1, 2026. Campbell University in North Carolina reported unauthorized access to one cloud-based data storage platform from March 31 through April 1, 2026, contained to that environment per the school. The investigation remained ongoing into affected individuals and data types; disclosed categories span extensive PHI and PII including medical, mental-health, financial, government ID, and student records. Campbell reported no evidence of misuse at notice time, notified federal law enforcement, and filed with HHS indicating at least 500 individuals' protected health information was involved while the final count remained pending. Separately, the Incransom ransomware group claimed the university on April 11, 2026 and threatened a 500 GB release—an unverified actor claim distinct from the university's confirmed access finding. HIPAA Journal summarized regulatory context June 26, 2026.
Root cause
Unauthorized access to a cloud-based data storage platform March 31–April 1, 2026; isolated to single platform per university