The University of Pennsylvania confirms that a recent cyberattack caused a major data theft



  • Hackers accessed university systems via stolen SSO credentials, stealing data from 1.2 million people
  • Offensive Mass Email Followed Partial Blocking; The university later confirmed that the rape was real.
  • The attack exploited weak MFA enforcement among senior staff through social engineering

It appears that the “obviously false” and “fraudulent” claims recently made by the University of Pennsylvania hackers are not so “obviously false” and “fraudulent” after all, as the organization has now confirmed that the hackers stole files from its systems.

Cybercriminals recently revealed that they had gained “full access” to a University employee’s PennKey SSO account, which gave them access to his VPN, Salesforce data, Qlik analytics platform, SAP business intelligence system, and SharePoint files. Using that access, they stole data from approximately 1.2 million students, alumni and donors.



Leave a Comment

Your email address will not be published. Required fields are marked *