Almeida Law Group is investigating a data breach at Monmouth University. The breach occurred on February 5th–13th, 2026 and was discovered on May 29th, 2026. If you were affected, contact Almeida Law Group.
About Monmouth University
Monmouth University is a private university founded in 1933, located at 400 Cedar Avenue in West Long Branch, New Jersey. It enrolls approximately 4,660 undergraduate and 1,750 graduate students and offers more than 50 undergraduate and graduate degree programs along with four doctoral programs. As an educational institution, Monmouth University collects and stores a wide range of personal information about students, faculty, staff, and others affiliated with the university.
What Happened?
Monmouth University was listed in a Texas Attorney General data security breach report published on July 1st, 2026. The filing identifies the incident as a data breach affecting 164,041 individuals in total. The breach window ran from February 5th, 2026 through February 13th, 2026, but was not formally discovered until May 29th, 2026—a delay of more than three months. Notice to affected consumers was provided by U.S. Mail. The compromised data includes names, addresses, Social Security numbers, driver’s license numbers, government-issued ID numbers, financial account information, medical information, health insurance information, and dates of birth.
The PEAR (Pure Extraction and Ransom) ransomware group claimed responsibility for the attack on March 26th, 2026, asserting it exfiltrated approximately 16 terabytes of data from the university. PEAR, which began claiming attacks in August 2025, does not encrypt victims’ data and instead focuses solely on data theft and extortion. Cybersecurity researcher Rebecca Moody of Comparitech noted that the claimed 16 TB haul was roughly 28 times greater than the average amount of data stolen in similar university attacks. University President Patrick Leahy first notified students by email on March 13th, 2026, and the university engaged the FBI and the Department of Education. Three federal class action lawsuits were filed in late March 2026 in the United States District Court for the District of New Jersey by former students Jordan Staub, Erin Masterson, and Matthew Englehardt, alleging that Monmouth University failed to adequately protect sensitive data and failed to follow minimum cybersecurity standards. At least one complaint estimates a proposed class of 100 or more members with claims exceeding $5 million.
Key Facts at a Glance
- Company or Organization: Monmouth University
- Industry: Higher Education (Private University)
- Location: West Long Branch, New Jersey
- Incident type: Data breach (PEAR ransomware group data theft and extortion)
- Date of breach: February 5th, 2026 – February 13th, 2026
- Date breach discovered: May 29th, 2026
- Date of consumer notification: July 1st, 2026 (published at OAG website; notice by U.S. Mail)
- Total persons affected: 164,041
- Litigation status: Three federal class action lawsuits filed in late March 2026 in the U.S. District Court for the District of New Jersey; additional law firms investigating claims
- Source: Texas Attorney General data security breach report (BR-0005153) — https://oag.my.site.com/datasecuritybreachreport/apex/DataSecurityReportsPage#BR-0005153; supplemental sources include https://www.classaction.org/data-breach-lawsuits/monmouth-university-march-2026, https://edscoop.com/monmouth-university-ransomware-pear/, and https://outlook.monmouth.edu/2026/04/lawsuits-mount-after-data-is-breached-in-cybersecurity-incident/
What Should You Do?
If you received a notification letter from Monmouth University, review it carefully for any identity theft protection enrollment offer and sign up before the deadline. Because this breach involved highly sensitive data—including Social Security numbers, financial account information, medical information, and health insurance information—you should consider placing a fraud alert or credit freeze with all three major credit bureaus (Equifax, Experian, and TransUnion). Monitor your bank and credit card accounts closely for any unauthorized activity, and request your free annual credit reports at AnnualCreditReport.com. If you suspect misuse of your information, report it at IdentityTheft.gov. Because medical and health insurance information was involved, also review any Explanation of Benefits statements from your insurer and check your medical records for services you did not receive.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.