{"id":25682,"date":"2025-11-05T15:47:07","date_gmt":"2025-11-05T15:47:07","guid":{"rendered":"https:\/\/www.newsbeep.com\/us-pa\/25682\/"},"modified":"2025-11-05T15:47:07","modified_gmt":"2025-11-05T15:47:07","slug":"university-of-pennsylvania-confirms-hacker-stole-data-during-cyberattack","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us-pa\/25682\/","title":{"rendered":"University of Pennsylvania confirms hacker stole data during cyberattack"},"content":{"rendered":"<p id=\"speakable-summary\" class=\"wp-block-paragraph\">The University of Pennsylvania confirmed on Tuesday that a hacker stole university data as part of <a href=\"https:\/\/techcrunch.com\/2025\/10\/31\/hackers-threaten-to-leak-data-after-breaching-university-of-pennsylvania-to-send-mass-emails\/\" rel=\"nofollow noopener\" target=\"_blank\">last week\u2019s data breach<\/a>, during which alumni and other affiliates received suspicious emails from official university email addresses.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe got hacked,\u201d the message from the hackers read. \u201cWe love breaking federal laws like FERPA (all your data will be leaked),\u201d the message added. \u201cPlease stop giving us money.\u201d<\/p>\n<p class=\"wp-block-paragraph\">While Penn initially told TechCrunch that the email was \u201cfraudulent,\u201d the university has now confirmed the hacker\u2019s claim that data was taken during the breach.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOn October 31, Penn discovered that a select group of information systems related to Penn\u2019s development and alumni activities had been compromised,\u201d the university wrote in a statement, which was emailed to alumni and <a rel=\"nofollow noopener\" href=\"https:\/\/view.connect.upenn.edu\/?qs=e6561da03501322708c8d3b0e72a1e4bbd12a6e47858cf629ae228ef1d538f7aa2b0b6b59ec76b94a32f2d063fd5225d71374aa4eba43217e3bbc051186d3ebf212990e0c0b9baed754e92083af57114b5986bf33459d239&amp;7194ef805fa2d04b0f7e8c9521f97343\" target=\"_blank\">shared online<\/a>. \u201cPenn\u2019s staff rapidly locked down the systems and prevented further unauthorized access; however, not before an offensive and fraudulent email was sent to our community and information was taken by the attacker.\u201d<\/p>\n<p class=\"wp-block-paragraph\">(Disclosure: As an alumna and former employee of the university, the hackers sent the message to my personal email three times, each coming from different official\u00a0@upenn.edu\u00a0email addresses, including one from a senior Penn staff member.)<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1172\" height=\"1200\" src=\"https:\/\/www.newsbeep.com\/us-pa\/wp-content\/uploads\/2025\/11\/redacted-upenn-screenshot-hack.webp.png\" alt=\"A partially redacted email sent by hackers with access to the university of Pennsylvania email system.&#10;\" class=\"wp-image-3065239\"  \/>A partially redacted email sent by hackers from a university of Pennsylvania email address.Image Credits:TechCrunch (Screenshot)<\/p>\n<p class=\"wp-block-paragraph\">The university said that the breach occurred due to a <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#social-engineering\" rel=\"nofollow noopener\" target=\"_blank\">social engineering<\/a> attack, a hacking technique in which individuals are tricked into handing over sensitive information like log-in credentials, perhaps through phishing or a phone call.<\/p>\n<p class=\"wp-block-paragraph\">A Penn employee, who we are not naming as they were not authorized to speak to the press, told TechCrunch that the university requires students, staff, and alumni to use <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#multi-factor-authentication\" rel=\"nofollow noopener\" target=\"_blank\">multi-factor authentication<\/a> (MFA) on their accounts as a security measure; however, the employee said that some high-ranking officials were granted exemptions to MFA requirements.<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch asked Penn about these alleged MFA exceptions, and if the university could provide a percentage of MFA adoption among staff. Penn spokesperson Ron Ozio declined to comment to TechCrunch beyond Penn\u2019s <a rel=\"nofollow noopener\" href=\"https:\/\/university-communications.upenn.edu\/data-incident?7194ef805fa2d04b0f7e8c9521f97343\" target=\"_blank\">official data incident page<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">As required by law, Penn said it will contact individuals whose personal information was accessed by hackers. The university has not said when these notifications will occur, how many people are affected, or what information was accessed.<\/p>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow noopener\" href=\"https:\/\/www.thedp.com\/article\/2025\/11\/penn-hack-documents-released-gse-emails-data\" target=\"_blank\">The Daily Pennsylvanian<\/a> reports that the alleged Penn hacker claimed to have taken documents relating to university donors, bank transaction receipts, and personally identifiable information. The hacker said they were financially motivated.<\/p>\n<p class=\"wp-block-paragraph\">Earlier this year, hackers breached Columbia University, accessing sensitive information about around <a rel=\"nofollow noopener\" href=\"https:\/\/www.insidehighered.com\/news\/tech-innovation\/administrative-tech\/2025\/08\/12\/hack-columbia-university-hits-870k-people\" target=\"_blank\">870,000 students and applicants<\/a>, including their Social Security numbers and citizenship status.<\/p>\n<p class=\"wp-block-paragraph\">Both the Penn and Columbia hacks appear motivated by discontent with affirmative action policies. In the email that the Penn hacker sent to the university community, the hacker wrote, \u201cWe hire and admit morons because we love legacies, donors, and unqualified affirmative action admits.\u201d Meanwhile, the Columbia hacker <a rel=\"nofollow noopener\" href=\"https:\/\/www.bloomberg.com\/news\/articles\/2025-07-01\/columbia-university-applicants-personal-data-stolen-by-hacker?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc1MTM5MTYwNiwiZXhwIjoxNzUxOTk2NDA2LCJhcnRpY2xlSWQiOiJTWUlZSEVUMEcxS1cwMCIsImJjb25uZWN0SWQiOiIzMEE2NDdGMEY4Qjc0NkM1QUQ4QjVBNkUxOUIyOTBEOSJ9.f_xRHO2J6g4EvwPZ6Q26itE90_TH0GO-L4lLqvRVS5Y&amp;leadSource=uverify%20wall&amp;embedded-checkout=true\" target=\"_blank\">told Bloomberg <\/a>that they sought to access data from the university to investigate its affirmative action practices. <\/p>\n<p class=\"wp-block-paragraph\">If you have more information about the Penn hack, you can contact Amanda Silberling securely on Signal at @amanda.100, or by email, from a non-work device.<\/p>\n","protected":false},"excerpt":{"rendered":"The University of Pennsylvania confirmed on Tuesday that a hacker stole university data as part of last week\u2019s&hellip;\n","protected":false},"author":2,"featured_media":21068,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[5962,28,30,29,4347],"class_list":{"0":"post-25682","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-pennsylvania","8":"tag-penn","9":"tag-pennsylvania","10":"tag-pennsylvania-headlines","11":"tag-pennsylvania-news","12":"tag-university-of-pennsylvania"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/posts\/25682","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/comments?post=25682"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/posts\/25682\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/media\/21068"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/media?parent=25682"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/categories?post=25682"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/tags?post=25682"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}