CSIDB logo
Incident

University of Pennsylvania

Incident posture

Attack window
Oct 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-13 02:50

Linked entities

Victim
University of Pennsylvania
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Oct 2025
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Pending

Summary

University of Pennsylvania experienced a data breach claimed by the cybercrime group ShinyHunters, which leaked additional internal files including donor records, internal communications, and personal information of high‑profile individuals such as members of the Trump family. The group said the release followed the university’s refusal to pay a ransom, and the incident led to multiple lawsuits that were later consolidated, while the university stated that fewer than ten individuals were affected and that it had completed a review and notified those impacted.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

3 techniques

Description

In October 2025, the University of Pennsylvania experienced a data breach that the university later described as affecting a select group of information systems related to its development and alumni activities. In November 2025, Penn officials confirmed the breach and noted that the attackers had sent alumni emails announcing the intrusion from official university addresses. The university attributed the incident to social engineering, explaining that the attackers had impersonated trusted individuals to trick employees into granting access. At that time, Penn did not disclose the specific categories of data that had been accessed, stating only that the compromised systems were tied to development and alumni functions.

In February 2026, the hacking group ShinyHunters claimed responsibility for the October 2025 breach and published what it said were more than one million records taken from Penn’s systems. The released material included internal donor records, internal talking points, a November 2023 progress report from the University Antisemitism Action Plan, and personal information of several high‑profile individuals, among them former President Donald Trump and members of his family, who had been labeled internally as 'Confirmed Ultra High Net Worth'. ShinyHunters asserted that the breach affected 1.2 million records, while Penn’s subsequent court filings maintained that the incident impacted fewer than ten individuals. Following the leak, eighteen Penn graduates filed class‑action lawsuits against the university, which were later consolidated by a district judge.

A Penn spokesperson told media outlets that the university had completed a comprehensive review of the cybersecurity incident and had notified any individuals determined to be affected. The spokesperson also said that Penn was analyzing the leaked data and would notify additional individuals if required by applicable privacy regulations. ShinyHunters stated that it had initially kept the stolen data private for a short period and intended to release it publicly within one to two months after using it, later telling a technology news outlet that it planned to sell the data before making it public. The group said it published the information because Penn had refused to pay a ransom or cooperate with its demands.

Sources

Sources available to members: 2 sources.

CSIDB