{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-princeton-advancement-database-breached-in-targeted-phishing-attack"},"incident":{"slug":"2025-princeton-advancement-database-breached-in-targeted-phishing-attack","title":"Princeton advancement database breached in targeted phishing attack","date":"2025-11","date_precision":"month","year":2025,"victim_org":"Princeton University","sector":"Education","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Princeton University disclosed in November 2025 that an attacker gained access to a database used by its advancement office after a targeted phishing attack against a university employee. Names, addresses, phone numbers, email addresses and donation-related information for alumni, donors, students, parents, faculty and staff were exposed. Princeton said Social Security numbers, passwords and financial account details were not stored in the affected database. Class-action suits followed.","how_it_worked":"The intrusion started with a targeted phishing approach aimed at a single staff member with advancement-system access rather than a mass campaign. The message and follow-up were crafted around university fundraising work, an area where staff routinely receive unfamiliar outreach about events, gifts and alumni records, which made the approach unremarkable. The trust signal abused was the appearance of legitimate internal or alumni-related correspondence; the pressure was ordinary work urgency rather than threats. Once the employee's session or credentials were captured, the attacker authenticated as them and queried the advancement database directly, exporting constituent records before the university detected the activity and cut off access.","lessons":"Hardware-backed or passkey MFA for advancement staff, plus alerting on unusual bulk queries against constituent databases, would have contained the single compromised account.","confidence":"Confirmed","sources":[{"title":"Princeton Database Breached in Targeted Phishing Incident","url":"https://paw.princeton.edu/article/princeton-database-breached-targeted-phishing-incident","publisher":"Princeton Alumni Weekly"},{"title":"Cybersecurity incident information and FAQ","url":"https://oit.princeton.edu/cybersecurity-incident-information-and-faq","publisher":"Princeton University OIT"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-princeton-advancement-database-breached-in-targeted-phishing-attack"}}