Harvard University
Incident posture
Linked entities
- Victim
- Harvard University
- Threat actors
- 1 actor
- Sources
- 2 sources
Timeline
Summary
A data breach originally discovered last year at the university escalated publicly when the ShinyHunters hacking group published what it claims are more than one million stolen records on its dedicated leak site after the institutions refused to pay a ransom. The stolen information, tied to fundraising and alumni engagement systems, included names, email addresses, phone numbers, home and business addresses, event attendance details, donation history, and other biographical data, with the leaked dataset verified in part against alumni records. Both organizations attributed the initial intrusions to social engineering, including voice phishing targeting employees and impersonation tactics used to gain access to development and alumni systems.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In November 2025, both Harvard University and the University of Pennsylvania confirmed data breaches affecting their alumni and development systems. UPenn disclosed that a "select group of information systems related to Penn's development and alumni activities" had been compromised, while Harvard later confirmed a breach of its alumni systems. The University of Pennsylvania attributed its incident to social engineering, in which attackers impersonated trusted individuals to trick employees or affiliates into granting access or divulging credentials. Harvard University attributed its breach to a voice phishing attack, commonly referred to as vishing, in which hackers called targets by voice and persuaded them to click a malicious link or open a harmful attachment. Both attacks targeted the systems used to support fundraising and alumni engagement rather than academic, research, or financial systems, focusing the impact on donor, alumni, and contact data rather than on educational records or instructional infrastructure.
Following the initial compromise, the threat actor responsible identified itself as ShinyHunters, a group known for data theft and extortion campaigns. During the UPenn breach, the hackers sent emails to alumni directly from official university email addresses, announcing the intrusion and including language that framed the attack in political terms, expressing discontent with affirmative action policies and criticizing legacy admissions and donor preferences. The group also used those communications to pressure the universities, signaling that exfiltrated data would be released if ransom demands were not met. In November 2025, in line with their typical tactics, ShinyHunters attempted to extort both universities by threatening to publish the stolen information unless payment was made. Both Harvard and the University of Pennsylvania declined to pay the ransom.
On February 4, 2026, ShinyHunters published what it claimed were more than one million records from each university on its dedicated leak site, a platform the group uses to publicly expose stolen data when extortion attempts fail. According to the group, the publication was a direct response to the universities' refusal to pay the ransom. TechCrunch reviewed portions of the published datasets and verified their authenticity by contacting affected alumni and cross-referencing the data against publicly available records, including student ID numbers. The published data appeared consistent with the descriptions both universities had previously provided regarding what was stolen.
The published datasets contained a range of personally identifiable information tied to alumni, donors, and university engagement activities. Harvard stated that the stolen information included email addresses, phone numbers, home and business addresses, event attendance records, details of donations made to the university, and other biographical information connected to its fundraising and alumni relations efforts. UPenn did not initially specify the exact data types compromised, indicating only that systems tied to development and alumni activities had been affected. Reports later indicated that the published records also included dates of birth and additional demographic attributes. The breadth of the data, including donation histories and biographical details, made the exposed records significantly more sensitive than simple email lists, raising concerns about identity theft, targeted phishing, social engineering, and potential blackmail of high-profile donors.
The operational and reputational consequences for both institutions were tied primarily to the public release of the data rather than to the initial intrusion itself, as the breaches did not involve encryption of systems in a ransomware-style disruption. Because the attacks focused on exfiltration with subsequent blackmail, the long-term impact derived from the public exposure of donor and alumni information, the loss of trust among those communities, and the regulatory obligations triggered by the disclosure of personal information. Penn spokesperson Ron Ozio stated that the university was "analyzing the data and will notify any individuals if required by applicable privacy regulations," indicating that notification procedures were being initiated in response to the publication. Harvard did not respond to a request for comment at the time the publication was reported.
The incident drew broader attention because it illustrated how attackers exploited organizational weaknesses, specifically in identity services and internal access controls, rather than relying on novel technical exploits. Both universities were compromised through human-targeted methods, voice phishing in the case of Harvard and broader social engineering in the case of UPenn, showing that attackers gained access by deceiving individuals with authority over sensitive systems. Once inside, the attackers focused on systems holding valuable personal and donor information, exfiltrated it, and then attempted to monetize the theft through extortion. The decision by both institutions not to pay the ransom led directly to the public release of the data in early February 2026, turning the incident from a private security matter into a publicly documented exposure affecting more than one million individuals associated with each university.
Sources
Sources available to members: 2 sources.