Boise State University Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Boise State
Active investigation Data breach · Education Notices mailed Sep 22, 2026

Received a September 2026 breach notice from Boise State?

Dapeer Law, P.A. is investigating a potential class action against Boise State University, a public university in Boise, Idaho, on behalf of students, faculty, and staff who rely on its single-sign-on (SSO) services and may have been affected by the September 2026 website-redirect security incident involving Elsevier academic resources.

Submit your claim → See what to do No fee unless we recover for you
Breach window
Sept 21 to 22, 2026
Malicious redirects on Elsevier-hosted sites
Notification delay
Under 1 day
Discovered Sep 21, 2026, notice filed Sep 22, 2026
Credit monitoring
None offered
No data exposure reported in the notice
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Boise State dated September 2026.
  • You use Boise State single-sign-on (SSO) to access Interfolio (Faculty 180) or other Elsevier academic resources.
  • You attempted to reach an Elsevier-hosted site on the evening of September 21, 2026, or you have since noticed phishing attempts or unusual activity in your academic or email accounts.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility →
Background

What happened

According to the notice filed with the Idaho Attorney General, Boise State discovered at 6:49 p.m. on September 21, 2026 that several Elsevier-hosted websites were automatically redirecting visitors to a page created by the hacking group LAPSUS$. Boise State immediately disabled single-sign-on (SSO) access to Interfolio (Faculty 180) and related Elsevier services as a precaution.

By 9:09 p.m. that evening, the malicious redirects had been removed. SSO access remained offline until 8:30 a.m. on September 22, 2026 while the university reviewed incident reports. The notice states that Boise State's internal systems were not directly affected, that Interfolio was not impacted, that no ransom demand was made, and that investigators found no evidence that personal data was viewed or exfiltrated. Boise State filed its notice with the Idaho Attorney General on September 22, 2026.

Even where no data theft has been confirmed, unauthorized redirects on sites used for university login can create follow-on risks, including credential phishing and account-takeover attempts aimed at people who use the affected services. Dapeer Law is reviewing whether affected users may have claims under Idaho and other state consumer-protection and data privacy laws.

Website redirect incident Single-sign-on (SSO) Elsevier academic resources Idaho Attorney General filing Higher education
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard any notice or email you received from Boise State about this incident. It documents when and how you were informed and may be important evidence if you decide to participate in a lawsuit.

2

Secure your SSO and email accounts

Boise State has not offered credit monitoring because it reports no data exposure. Change your Boise State password if you entered it on any unfamiliar page, enable multi-factor authentication, and be cautious of emails or login prompts that reference Elsevier, Interfolio, or Faculty 180. Taking these protective steps does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. If you entered your university credentials on a page you were redirected to, also watch for password-reset emails and login alerts you did not request.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your situation, explain your options under Idaho and other state consumer-protection and data privacy laws, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim →
Timeline

Breach timeline

Sep 21, 2026, 6:49 p.m. Passed
Malicious redirects on Elsevier-hosted sites discovered, SSO disabled
Sep 21, 2026, 9:09 p.m. Passed
Malicious redirects removed
Sep 22, 2026, 8:30 a.m. Passed
SSO access to Elsevier services restored
Sep 22, 2026 Passed
Notice filed with Idaho Attorney General
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, account takeover from phished credentials, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Boise State University to implement stronger safeguards for its single-sign-on services and the third-party academic platforms it connects users to.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Boise State. What should I do? +

Keep any notice or email you received from Boise State about the incident. Change your university password if you entered it on an unfamiliar page, turn on multi-factor authentication, and monitor your academic and email accounts for unusual activity or phishing messages. Consider speaking with a data breach attorney about your rights.

Am I eligible to join a class action against Boise State? +

If you use Boise State SSO to access Interfolio (Faculty 180) or other Elsevier resources, and you experienced financial loss, account compromise, service disruption, or other harm connected to the incident, you may qualify. Eligibility depends on your individual facts and state of residence. A free consultation can clarify where you stand.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

According to the notice filed with the Idaho Attorney General, Boise State reports no evidence that any personal or sensitive information was viewed or exfiltrated. The incident is described as malicious redirects placed on several Elsevier-hosted websites. If you received an individual notice, check it for any details specific to you.

Did Boise State offer free credit monitoring? +

No. Boise State did not offer credit monitoring because investigators found no evidence of data exposure. You can still request free credit reports and place a no-cost fraud alert or credit freeze with the three bureaus. Taking these steps does not waive your right to pursue a claim.

How many people were affected by the Boise State breach? +

The notice filed with the Idaho Attorney General does not specify how many people were affected. The incident primarily involved users who attempted to access Elsevier platforms during the redirect window on September 21, 2026. This page will be updated as more information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

Boise State filed its notice with the Idaho Attorney General, which publishes it on its website. You can download it using the official notice link on this page, or contact Dapeer Law and we can help you obtain a copy during a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Boise State University, Elsevier, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with Idaho Attorney General on September 22, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Ethan Conrad Properties Data Breach Lawsuit Investigation

Next
Next

Peña & Bromberg Data Breach Lawsuit Investigation