‘We have terrible security practices’ – University of Pennsylvania hackers say they stole over a million records in major cyber attack


  • The attacker gained access to the university’s systems via compromised SSO and stole data on 1.2 million individuals
  • Offensive mass email sent after broadcast using retained access to Salesforce Marketing Cloud
  • Stolen data includes PII, financials and demographics; the attacker targets rich donors, no ransom is planned

Cybercriminals have claimed responsibility for the latest cyberattack on the University of Pennsylvania, claiming they stole data on approximately 1.2 million students, alumni and donors.

This was told by an unnamed threat actor Bleeping Computer they gained “full access” to a university employee’s PennKey SSO account, which gave them access to Penn’s VPN, Salesforce data, Qlik analytics platform, SAP business intelligence system and SharePoint files.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top