CSIDB logo
Incident

University of Pennsylvania

Incident posture

Attack window
Aug 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:24

Linked entities

Victim
University of Pennsylvania
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Aug 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The University of Pennsylvania was among the higher education institutions impacted by a security incident linked to a zero-day vulnerability in Oracle's E-Business Suite software, with the CL0P ransomware group exploiting the flaw to access sensitive records. The breach at UPenn exposed approximately 46,000 records as part of a broader campaign which hit several universities through the same third-party software weakness. Separately, the university experienced another incident involving the exfiltration of personal data including names, email addresses, home addresses, dates of birth, and donation-related information, which was later published online by the threat actor claiming responsibility, accompanied by an extortion demand rather than traditional encryption-based ransomware. This dual exposure illustrates how both supply-chain vulnerabilities and targeted attacks against identity services can combine to elevate the severity of consequences for affected institutions and their communities.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The University of Pennsylvania was among a group of higher education institutions impacted by a cybersecurity incident in 2025 linked to a zero-day vulnerability in Oracle's E-Business Suite software, which was exploited by the ransomware group CL0P in August 2025. The breach stemmed not from a direct attack on the university's own systems but from a flaw in third-party software used by the institution. CL0P exploited the unknown vulnerability to gain access to data held by multiple organizations, and the University of Pennsylvania was confirmed as one of the affected parties. According to Comparitech's education ransomware roundup, the Oracle E-Business Suite exploit accounted for the top three cyber attacks on the higher education sector in 2025, and the University of Pennsylvania incident was associated with approximately 46,000 records being breached. The broader campaign also impacted the University of Phoenix, which suffered exposure of 3.5 million records, and Dartmouth College, which saw nearly 100,000 records affected.

Beyond the Oracle-related incident, the University of Pennsylvania was also referenced in connection with a separate data exposure event alongside Harvard University. Reports published in early February 2026 indicated that personal data records exfiltrated from Harvard and the University of Pennsylvania had been published in large quantities. The published data reportedly included contact details, dates of birth, addresses, and other sensitive attributes, with some sources indicating that the information extended to demographic and donation-related data. The incident was characterized not as a classic ransomware event involving encryption of systems, but as an exfiltration with a blackmail logic, where the primary threat stemmed from the potential public release of stolen information. ShinyHunters was identified as the actor or claiming entity associated with the publication of the exfiltrated Harvard and UPenn data.

The timing of these events highlights a pattern in which the initial compromise occurred prior to the public reporting cycle, with the escalation taking place through the later publication of the stolen data. The University of Pennsylvania's appearance in both the Oracle/CL0P-related breach statistics and the Harvard data publication reporting suggests that the institution faced multiple distinct security events during this period, or that the events were characterized differently across reporting sources. The exposure of personal information including names, email addresses, physical addresses, and dates of birth carries significant implications for affected individuals, as such data combinations are recognized as suitable for targeted phishing, identity theft, and other follow-on fraudulent activities. Comparitech's analysis noted that third-party software vulnerabilities were a major driver of record exposure in the higher education sector during 2025, making it more difficult for institutions to secure their environments when vulnerabilities exist in vendor systems.

Sources

Sources available to members: 2 sources.

CSIDB