Skip to content

University of Pennsylvania Cyberattack

Summary

University of Pennsylvania logo

Attackers used social engineering to access University of Pennsylvania alumni and development systems Oct. 31, 2025, sent fraudulent mass emails and took data. Penn said affected systems were restored by Nov. 4. ShinyHunters later claimed responsibility and published files; independent reporting verified some Penn data, but the group’s 1.2 million-record claim conflicts with Penn’s account. No encryption or clinical outage was established.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Critical infrastructure sector

Incident characteristics

Assessments

Incident narrative

Analyst assessment

We reported Oct. 31 that Penn-affiliated accounts sent fraudulent mass emails to students, staff and alumni. Penn’s subsequent statement confirmed that social engineering gave attackers access to a select group of development and alumni information systems, that information was taken and that Penn locked those systems down. This is a confirmed intrusion with a limited, documented interruption to affected university IT operations and misuse of outbound communications.

Operational effects

The university and Penn Medicine IT warned recipients about widespread fraudulent messages and worked to block more. Penn said all affected systems had been restored and were fully operational by its Nov. 4 message. The exact lockdown duration and effect on ordinary teaching, clinical care or other university systems are not established. The incident is mapped to the university’s Philadelphia campus city only; Penn Medicine did not report a clinical outage.

Data scope

Penn confirmed information was taken. In February 2026, a university spokesperson said a comprehensive review of the downloaded files was complete and notifications went to a limited number of people whose personal information was impacted. The Philadelphia Inquirer reported that fewer than 10 people received legally required notices, citing a legal filing and a Penn source. This does not measure all downloaded records or message recipients. Attackers claimed 1.2 million records, which Penn disputed; no verified figure for all obtained material was provided. A separate later Oracle E-Business Suite breach is outside this entry.

ShinyHunters claim and publication

In February 2026, ShinyHunters claimed responsibility and published files it said came from the Penn intrusion. TechCrunch said it verified part of the dataset against alumni and public records. A Daily Pennsylvanian interview with a person it verified could edit the group’s leak forum reported the group’s claim that it demanded $1 million and released files after Penn did not pay. These reports substantiate a public extortion claim and publication of some Penn information, but they do not establish the group’s precise membership, validate its claimed 1.2 million records or indicate that ransomware encrypted Penn systems. Penn’s limited legal notification count addresses a different question from the size of the published dataset.

Threat actor and claim

Listed as: University of PennsylvaniaSource: ransomware.live

Claim details

ShinyHunters claimed the October 2025 intrusion, a $1 million demand and publication of files in February 2026. TechCrunch verified part of the published dataset; Penn disputes the 1.2 million-record count. Encryption was not reported.

Organizations involved

Impacted location

Sources

University of Pennsylvania probes mass email breach

Fraudulent mass emails from university-associated addresses reached students, staff and alumni; Penn security team responded.

Regarding Spam Emails

University and Penn Medicine IT communities were taking steps to stop widely distributed spam emails.

Penn says investigation into October 2025 cybersecurity breach is complete

Penn spokesperson said review of downloaded files was complete and the limited number of people with impacted personal information had been notified.

See something that needs correction?

Signed-in members can report an error, update, or missing source.