St. Thomas to settle data breach lawsuit. Here’s how to file a claim

The Chapel of St. Basil on the University of St. Thomas campus was designed by renowned architect Philip Johnson with three simple forms: a cube, a dome and a wall that pierces them both. 

The Chapel of St. Basil on the University of St. Thomas campus was designed by renowned architect Philip Johnson with three simple forms: a cube, a dome and a wall that pierces them both. 

Richard Payne/Courtesy

University of St. Thomas students, employees and alumni whose personal information was compromised in a 2025 data breach may be eligible for some relief after the institution received preliminary approval to settle a class action lawsuit.  

The private Catholic university in Houston reached an agreement in late May in state district court that allows affected people to claim three years of credit monitoring and between $100 and $4,500 each, depending on the losses caused by the breach.  

‘A NEW ERA OF CHANGE’: Pope Leo’s encyclical calls to ‘disarm AI.’ An expert weighs in on what that means for students, teachers.

Article continues below this ad

ransomware company took credit for the hack that downed the private Catholic university’s servers for more than a week at the beginning of the fall 2025 semester, according to the lawsuit. A former student and employee filed the suit in October, alleging that St. Thomas failed to protect a “treasure trove” of personal information and didn’t notify members of the campus in a timely manner when it was hacked and posted on the dark web.  

The settlement is not an admission of liability. The plaintiffs said that they believe their claims have merit, while the university has continued to deny the allegations. It decided to settle because of the time and cost of continuing to fight the case, according to the agreement.  

In a statement, St. Thomas officials said that the institution remains “deeply committed to the privacy and security of all members of our UST community.” They cited university policy preventing them from further comment. 

“We have resolved this matter in a manner we believe is in the best interests of our mission, our students, faculty, staff, alumni, donors and the whole UST community,” they said. “We are grateful to move forward and remain focused on our work and our mission to serve our students. We recognize the seriousness of this and sincerely regret any concern or inconvenience this may have caused.” 

Article continues below this ad

People who received a letter notifying them of the settlement can submit their claims by Sept. 28 for out-of-pocket expenses that were not reimbursed and were “fairly traceable” to the breach. The amounts vary, and the claims require proof, such as official receipts.

People can receive up to $4,500 for “extraordinary losses” stemming from fraud or identity theft that was “more likely than not” caused by the breach. 

Others can receive up to $500 for “ordinary losses,” covering attorneys’ or credit repair service fees; costs associated with freezing or unfreezing credit; and credit monitoring costs. Or, people can receive a $100 payment if they show their personal information was exposed.  

Any of those individuals can also claim three years of credit monitoring and identity theft protection services with a bureau chosen by the university, including theft protection insurance.   

If affected people opt not to make a claim for documented out-of-pocket losses or credit monitoring, they can instead receive an alternative cash payment of $50. 

Article continues below this ad

It was not immediately known how much the university expects to pay in the settlement. Former student and employee Amy Crull, who filed the lawsuit, was expected to receive a $4,000 service award for representing the class. They also negotiated St. Thomas to pay up to $240,000 for attorneys’ fees.  

Attorneys for the plaintiff and settlement class did not respond to requests for comment. 

The breach 

The university’s servers went dark on Aug. 12 as the fall 2025 semester approached, preventing students from accessing online resources like financial aid and course registration before the first day of class.  

The next day, university officials said in a campus-wide email that they proactively quarantined the affected servers when an unauthorized party tried to access the system, but had not found any evidence of compromised information.  

Article continues below this ad

HIGHER ED: St. Thomas wins 10-year accreditation renewal

An investigation with third-party specialists later found that “there was unauthorized access to certain systems” even earlier, from July 25 to Aug. 12, and that “certain files” were accessed or taken, according to a description of the event, posted on the university website. It states that the university became aware of the activity on or about Aug. 12 and immediately took steps to secure the network. They also notified law enforcement. 

In September, university President Sinda Vanderpool confirmed that specialists were determining the scope of the “data impacted” and any affected individuals. She said they would receive a formal notification after the investigation’s completion, and she followed up with an email offering students, faculty and staff free credit monitoring codes in the meantime.  

In October, some students and faculty told the Houston Chronicle they had not been informed about the extent of the breach.  

The breach included documents appearing to detail investigations into student complaints of sexual harassment and misconduct by professors. Both students and accused employees were named. Also posted were documents detailing confidential settlement and payout agreements between the university and some of its former top-level leaders, the plaintiff alleged. 

Article continues below this ad

Crull filed the lawsuit after news reports about the breach, according to court documents. In her original filing, she accused the university of failing to safeguard students’ and employees’ personal information.  

She also alleged in the suit that that the university “obfuscated the nature of the breach and the threat it posed – refusing to tell its employees and students how many people were impacted, how the breach happened, when it was discovered, or why defendant is delaying notifying victims.” 

The settlement website, ustdatasettlement.com, contains more information about how to submit a claim.  

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *