University of Pennsylvania
Incident posture
Linked entities
- Victim
- University of Pennsylvania
- Threat actors
- 1 actor
- Sources
- 2 sources
Timeline
Summary
University of Pennsylvania experienced a data breach claimed by the cybercrime group ShinyHunters, which leaked additional internal files including donor records, internal communications, and personal information of high‑profile individuals such as members of the Trump family. The group said the release followed the university’s refusal to pay a ransom, and the incident led to multiple lawsuits that were later consolidated, while the university stated that fewer than ten individuals were affected and that it had completed a review and notified those impacted.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In October 2025, the University of Pennsylvania experienced a data breach that the university later described as affecting a select group of information systems related to its development and alumni activities. In November 2025, Penn officials confirmed the breach and noted that the attackers had sent alumni emails announcing the intrusion from official university addresses. The university attributed the incident to social engineering, explaining that the attackers had impersonated trusted individuals to trick employees into granting access. At that time, Penn did not disclose the specific categories of data that had been accessed, stating only that the compromised systems were tied to development and alumni functions.
In February 2026, the hacking group ShinyHunters claimed responsibility for the October 2025 breach and published what it said were more than one million records taken from Penn’s systems. The released material included internal donor records, internal talking points, a November 2023 progress report from the University Antisemitism Action Plan, and personal information of several high‑profile individuals, among them former President Donald Trump and members of his family, who had been labeled internally as 'Confirmed Ultra High Net Worth'. ShinyHunters asserted that the breach affected 1.2 million records, while Penn’s subsequent court filings maintained that the incident impacted fewer than ten individuals. Following the leak, eighteen Penn graduates filed class‑action lawsuits against the university, which were later consolidated by a district judge.
A Penn spokesperson told media outlets that the university had completed a comprehensive review of the cybersecurity incident and had notified any individuals determined to be affected. The spokesperson also said that Penn was analyzing the leaked data and would notify additional individuals if required by applicable privacy regulations. ShinyHunters stated that it had initially kept the stolen data private for a short period and intended to release it publicly within one to two months after using it, later telling a technology news outlet that it planned to sell the data before making it public. The group said it published the information because Penn had refused to pay a ransom or cooperate with its demands.
Sources
Sources available to members: 2 sources.