Claim details
ShinyHunters claimed the October 2025 intrusion, a $1 million demand and publication of files in February 2026. TechCrunch verified part of the published dataset; Penn disputes the 1.2 million-record count. Encryption was not reported.
Attackers used social engineering to access University of Pennsylvania alumni and development systems Oct. 31, 2025, sent fraudulent mass emails and took data. Penn said affected systems were restored by Nov. 4. ShinyHunters later claimed responsibility and published files; independent reporting verified some Penn data, but the group’s 1.2 million-record claim conflicts with Penn’s account. No encryption or clinical outage was established.
We reported Oct. 31 that Penn-affiliated accounts sent fraudulent mass emails to students, staff and alumni. Penn’s subsequent statement confirmed that social engineering gave attackers access to a select group of development and alumni information systems, that information was taken and that Penn locked those systems down. This is a confirmed intrusion with a limited, documented interruption to affected university IT operations and misuse of outbound communications.
The university and Penn Medicine IT warned recipients about widespread fraudulent messages and worked to block more. Penn said all affected systems had been restored and were fully operational by its Nov. 4 message. The exact lockdown duration and effect on ordinary teaching, clinical care or other university systems are not established. The incident is mapped to the university’s Philadelphia campus city only; Penn Medicine did not report a clinical outage.
Penn confirmed information was taken. In February 2026, a university spokesperson said a comprehensive review of the downloaded files was complete and notifications went to a limited number of people whose personal information was impacted. The Philadelphia Inquirer reported that fewer than 10 people received legally required notices, citing a legal filing and a Penn source. This does not measure all downloaded records or message recipients. Attackers claimed 1.2 million records, which Penn disputed; no verified figure for all obtained material was provided. A separate later Oracle E-Business Suite breach is outside this entry.
In February 2026, ShinyHunters claimed responsibility and published files it said came from the Penn intrusion. TechCrunch said it verified part of the dataset against alumni and public records. A Daily Pennsylvanian interview with a person it verified could edit the group’s leak forum reported the group’s claim that it demanded $1 million and released files after Penn did not pay. These reports substantiate a public extortion claim and publication of some Penn information, but they do not establish the group’s precise membership, validate its claimed 1.2 million records or indicate that ransomware encrypted Penn systems. Penn’s limited legal notification count addresses a different question from the size of the published dataset.
ShinyHunters claimed the October 2025 intrusion, a $1 million demand and publication of files in February 2026. TechCrunch verified part of the published dataset; Penn disputes the 1.2 million-record count. Encryption was not reported.

Philadelphia campus city anchor; no particular campus building or Penn Medicine clinical site outage established.
Fraudulent mass emails from university-associated addresses reached students, staff and alumni; Penn security team responded.
University and Penn Medicine IT communities were taking steps to stop widely distributed spam emails.
TechCrunch reported receiving fraudulent messages from official Penn addresses and obtained a university response.
Contemporaneous reporting documented fraudulent messages from multiple Penn-affiliated addresses and Penn’s response.
Penn said social engineering compromised development and alumni systems Oct. 31; it locked down systems, confirmed information taken, and said all systems had been restored.
Penn spokesperson said review of downloaded files was complete and the limited number of people with impacted personal information had been notified.
Legal filing and a Penn source indicated fewer than 10 people received legally required personal-information notifications.
TechCrunch reported a ShinyHunters leak and verified part of the Penn dataset against alumni and public records.
A person the paper verified could edit the group’s leak forum alleged a $1 million demand and nonpayment.
ShinyHunters listing alleges 1.2 million records; Penn disputes that figure.
Signed-in members can report an error, update, or missing source.