Cornell implemented a 16 character minimum for all NetID passwords as part of an effort to strengthen safeguards against cybersecurity threats, per a July 8 email from Cornell IT. This is a change from the previous standards, which required at least eight characters and three special characters, according to a University spokesperson.
All NetID passwords created after Feb. 14, when “enhanced” encryption standards were put into effect, must be updated, according to the IT@Cornell website.
This change comes in response to a recent string of cyber security incidents, alongside the “broader cybersecurity environment,” according to a statement from Robert Edamala, Cornell’s chief information security officer.
“Cornell and many of our peer institutions have been targets of attacks that began with compromised credentials or passwords,” Edamala wrote. “Strengthening password protections is part of reducing risk from those threats.”
On May 7, during the University’s final exam study period, a cybersecurity attack disabled Canvas, an online learning platform utilized by Cornell and many universities, for approximately six hours. The attack, which affected 9,000 schools, came from ShinyHunters, a cyber criminal group that specializes in large-scale data breaches and extortion.
Other recent cybersecurity attacks include a ransomware attack that disrupted City Bucks usage in February, a March data breach at Weill Cornell where a former employee gained access to patients’ medical records and a phishing scheme in July 2025 with “a level of sophistication that ha[d] not been seen previously,” according to an IT@Cornell webpage.
“Strong, recently set passwords are an important safeguard against compromised credentials, which continue to be one of the most common ways attackers gain access to systems,” Edamala wrote.
In his statement, Edamala explained that Cornell is aiming to achieve the “best practice” of switching from traditional passwords to “passphrases.”
“IT at Cornell recommends using a phrase or a series of unrelated words rather than a traditional password,” Edamala wrote.
He also explained that the change reflects an increase in cyberattacks “associated with current geopolitical tensions.”
Higher education institutions — especially those with large endowments — pose a lucrative target for hackers, who are often motivated by the large amount of money available, or the ability to make a political statement, according to Inside Higher Education. These attacks jumped 23% in the first half of 2025, with education being the fourth most targeted sector, according to Higher Ed Dive.
Edamala explained the University will continue to take measures to reduce these threats.
“The university continually evaluates our cybersecurity practices and makes changes to address emerging threats,” he wrote. “When cybersecurity enhancements require action from the community, they are announced.”

Everett Chambala is a member of the Class of 2027 in the School of Industrial and Labor Relations. He is an assistant news editor for the 144th Editorial Board and can be reached at echambala@cornellsun.com.








