The University of Pennsylvania has been the focus of a major cyberattackafter students and alumni began receiving offensive emails that appeared to come from official accounts at the institution. The messages, sent through the connect.upenn.edu, claimed that the university had been hacked and that sensitive data had been stolen.

Initially, the institution downplayed the incident, describing the emails as “obviously fake” and the result of a malicious act . However, a hacker later publicly claimed responsibility, revealing that the breach was much more extensive than the university had believed.
See also: Jabber Zeus developer 'MrICQ' detained in the US
Full access to critical systems
According to hackers who told BleepingComputer, the group gained full access to multiple university systems by exploiting an employee's SSO (PennKey) account. Through this breach, the attackers claim to have accessed the VPN , Salesforce Marketing Cloud , Qlik Analytics Platform , SAP Business Intelligence , and SharePoint and Box files .
The data allegedly stolen includes personal information on 1.2 million students, alumni and donors, including names, dates of birth, addresses, phone numbers and – most worryingly – demographic and financial data such as net worth, religion, race and sexual orientation.
“Revenge” via Salesforce
When the compromised employee account was eventually locked, the hackers still retained access to Salesforce Marketing Cloud and used it to send the offensive mass email to approximately 700,000 recipients. The email contained statements against the university itself, accusing it of “meritocracy” and “violation of federal laws,” while mocking the culture of elite US universities.
See also: Akira Ransomware: 23GB of data stolen from Apache OpenOffice?

The 1.7 GB file bomb
To prove their claims, the hackers published screenshots and sample data, and shortly afterwards they posted a 1.7GB file containing spreadsheets and files from internal systems . Although the university has not confirmed the authenticity of the files, the leak is already causing concern in the international academic community.
Without blackmail, but with a clear goal
Interestingly, the perpetrators claim they had no intention of extorting money from the university. “We don’t think they’ll pay, and we can exploit the data ourselves,” they said. The real target, they said, was the database donor, which contains high-value information about wealthy individuals and corporate donors.
Although this database has not yet been leaked, the hackers claim that they intend to make it public in the coming months, which could seriously damage the university's reputation and relations with its supporters.
Reactions and investigations
The University of Pennsylvania said it is continuing to investigate the case in collaboration with cybersecurity experts and authorities. So far, the extent of the leak has not been confirmed or whether the stolen data is authentic, but authorities are treating the case as a possible serious breach of critical infrastructure.

What does this mean for donors and alumni?
Experts warn that the leaked information could be used in targeted phishing and social engineering attacks. Hackers may try to impersonate the university, asking for “donations” or trick donors into giving up additional information or financial details.
See also: State hackers develop new Airstalk malware
Donors and alumni are urged to be suspicious of any unexpected email requesting money or information, and to verify the authenticity of any communication directly with Penn before responding.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Ethical and technological questions
The Penn case has once again brought to the fore the issues of privacy management at universities and how vulnerable even the most advanced educational structures remain. Despite investments in security technologies, human negligence – or a single weak point – can open the door to a cyber disaster.
Source: www.bleepingcomputer.com
