Breach report · Education

Kaplan North America Data Breach Impacts 173,000 Individuals

A Kaplan North America breach exposed the names, Social Security numbers and driver's license numbers of 173,676 people during a multi-week intrusion.

Timeline of the Breach

According to regulatory disclosures:

  • Unauthorized access occurred between October 30, 2025 and November 18, 2025
  • Affected individuals were not notified until March 17, 2026

The several-month gap between discovery and notification may draw regulatory scrutiny under state and federal breach disclosure laws.

What Information Was Compromised?

The breach reportedly involved highly sensitive personal data, including:

  • Full names
  • Social Security numbers
  • Driver’s license numbers

Unlike many recent breaches involving only contact information, this dataset contains identity-critical information that significantly increases the risk of fraud and identity theft.

Potential Risks to Affected Individuals

Exposure of Social Security numbers and driver’s license information creates elevated risk for:

  • Identity theft
  • Credit fraud
  • Tax fraud
  • Synthetic identity creation
  • Long-term financial harm

Because these identifiers cannot easily be changed, the impact may persist well beyond the initial disclosure.

The delay between the intrusion period (October–November 2025) and public notification (March 2026) could raise compliance questions under breach notification statutes.

A law firm has announced an investigation into the incident and potential legal claims, signaling possible litigation or class action activity.

Why This Matters

Education service providers maintain large volumes of sensitive personal data across students, instructors, and staff.

This breach highlights several recurring risk themes:

  • Extended attacker dwell time
  • Delayed disclosure timelines
  • High-value identity data exposure
  • Regulatory and legal fallout following notification

Organizations handling Social Security numbers and government-issued IDs must maintain:

  • Strong access controls
  • Continuous monitoring
  • Rapid incident detection
  • Clear breach notification protocols

When highly sensitive identity data is involved, the stakes increase significantly.

More from the feed

Other incidents we've written up.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.