Lee University notifies about 137,000 people a year after network breach

Organization
Lee University
Exploit
Ransomware
Industry
Education

Lee University, a private Christian institution in Cleveland, Tennessee, disclosed on 25 March 2025 that an unauthorized party had accessed its network a year earlier through a vulnerability in third-party software the university used. The Medusa ransomware group had claimed the intrusion on its leak site in April 2024, saying it took nearly 388 GB of data, and demanded $1 million. Lee University has not verified that claim.

In filings with state regulators, including the New Hampshire Attorney General, the university said the intrusion took place in March 2024, that it contained the incident and engaged outside cybersecurity specialists, and that its review established some data had been downloaded from its systems. Notification letters went out on 24 and 25 March 2025. The university had sent preliminary emails to some potentially affected people in November 2024.

The categories of information involved varied by individual and, according to the notices, could include names, Social Security numbers, driver's license and other government identification numbers, financial account information and medical information. Breach-tracking records citing multiple state attorney general filings put the number of people notified at 136,928.

Within two weeks of the notification, several proposed class actions were filed in federal court in Chattanooga. The complaints alleged that Lee failed to implement adequate and reasonable cybersecurity measures and that it waited roughly a year to tell affected people. They sought unspecified damages and lifetime credit monitoring for the class.

Updates

  1. The class action settled for 1.75 million dollars, covering the roughly 136,928 people notified. The court granted preliminary approval on 18 May 2026 and set a final approval hearing for 3 September 2026.

Sources