{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-university-of-pennsylvania-donor-systems-breached-via-social-engineering"},"incident":{"slug":"2025-university-of-pennsylvania-donor-systems-breached-via-social-engineering","title":"University of Pennsylvania donor systems breached via social engineering","date":"2025-10-31","date_precision":"day","year":2025,"victim_org":"University of Pennsylvania","sector":"Education","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"The University of Pennsylvania confirmed that a hacker stole data from systems supporting its development and alumni activities, with the incident discovered on 31 October 2025. Penn attributed the compromise to a social engineering attack in which someone was tricked into handing over login credentials. The attacker also used a compromised account to send abusive mass email to Penn constituents and claimed to hold donor documents and bank transaction records.","how_it_worked":"Penn said the intrusion began with social engineering that tricked an individual into giving up login credentials, and reporting noted that some senior staff held exemptions from the university's multi-factor authentication requirement, which removed the backstop that would normally have blunted a stolen password. The pretext targeted people working in development and alumni relations, whose accounts unlock both donor databases and mass-email tooling. After authenticating, the attacker pulled constituent records and then used the same access to blast offensive messages to alumni and donors, converting a quiet data theft into a public humiliation and extortion play.","lessons":"No MFA exemptions for executives or fundraising leadership, and separate authorisation for mass-email sending, would have limited both the theft and the follow-on abuse.","confidence":"Confirmed","sources":[{"title":"University of Pennsylvania confirms hacker stole data during cyberattack","url":"https://techcrunch.com/2025/11/05/university-of-pennsylvania-confirms-hacker-stole-data-during-cyberattack/","publisher":"TechCrunch"},{"title":"University of Pennsylvania confirms data stolen in cyberattack","url":"https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-confirms-data-stolen-in-cyberattack/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-university-of-pennsylvania-donor-systems-breached-via-social-engineering"}}