‘We have terrible security practices’ – University of Pennsylvania hackers claim to have stolen more than 1 million records in major cyberattack


  • The attacker accessed university systems via compromised SSO, stealing the data of 1.2 million people.
  • Offensive bulk emails sent after ejection using retained access to Salesforce Marketing Cloud
  • Stolen data includes personal information, financial and demographic data; attacker targets wealthy donors, no ransom expected

Cybercriminals have claimed responsibility for the recent cyberattack on the University of Pennsylvania, claiming to have stolen data on approximately 1.2 million students, alumni and donors.

An anonymous threat actor said BeepComputer they gained “full access” to a university employee’s PennKey SSO account, which gave them access to Penn’s VPN, Salesforce data, the Qlik analytics platform, the SAP business intelligence system, and SharePoint files.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top