What happened
The University of Pennsylvania confirmed that a hacker stole data from systems supporting its development and alumni activities, with the incident discovered on 31 October 2025. Penn attributed the compromise to a social engineering attack in which someone was tricked into handing over login credentials. The attacker also used a compromised account to send abusive mass email to Penn constituents and claimed to hold donor documents and bank transaction records.
How the deception worked
Penn said the intrusion began with social engineering that tricked an individual into giving up login credentials, and reporting noted that some senior staff held exemptions from the university's multi-factor authentication requirement, which removed the backstop that would normally have blunted a stolen password. The pretext targeted people working in development and alumni relations, whose accounts unlock both donor databases and mass-email tooling. After authenticating, the attacker pulled constituent records and then used the same access to blast offensive messages to alumni and donors, converting a quiet data theft into a public humiliation and extortion play.
The control that would have caught it· our reading, not a claim from the sources
No MFA exemptions for executives or fundraising leadership, and separate authorisation for mass-email sending, would have limited both the theft and the follow-on abuse.
Sources (2)
- University of Pennsylvania confirms hacker stole data during cyberattackTechCrunch·techcrunch.comOpen ↗
- University of Pennsylvania confirms data stolen in cyberattackBleepingComputer·bleepingcomputer.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.