Skip site navigation

Incidents

Privacy Notice

Incidents

Pursuant to MD State Government Code § 10-13A-04(B)(3), the University of Maryland College Park (“UMD”) provides the following notice regarding a breach of the security of a system involving personally identifiable information:

 

What happened?

 

On March 7, 2025, UMD received notice that some administrator accounts within an obsolete, but still online, email server for the National Socio-Environmental Synthesis Center (“SESYNC”) had been compromised. After internal investigation, it was determined that throughout December 2024, attackers downloaded the contents of the email server. 

 

What Information was involved?

 

The data involved in this incident included: full or partial name, social security numbers, passport numbers, credit card numbers, and bank account numbers of approximately 1,100 individuals.

 

What UMD has done in response:

  1. The email server has been taken offline and UMD is reviewing its policies and procedures so that appropriate security measures are taken to prevent such an incident from occurring again. 
  2. UMD has notified the FBI, all three of the United States’ credit agencies, and applicable state agencies of this incident. 
  3. UMD has notified all impacted individuals and has partnered with Experian to make identity detection and resolution services available to those individuals at no charge.

     

If you have not received a notification from UMD about this incident, your data was not impacted. 

If you have questions, please contact umd-privacy@umd.edu.