‘We have terrible security practices’: University of Pennsylvania hackers say they have stolen more than a million records in major cyberattack



  • Attacker accessed university systems through compromised SSO and stole data from 1.2 million people
  • Offensive Mass Email Sent After Ban Using Retained Access to Salesforce Marketing Cloud
  • The stolen data includes PII, financial and demographic; Attacker targets wealthy donors, no ransom planned

Cybercriminals have claimed responsibility for the recent cyberattack on the University of Pennsylvania, claiming they stole data from approximately 1.2 million students, alumni and donors.

An anonymous threat actor said beepcomputer gained “full access” to a University employee’s PennKey SSO account, which gave them access to Penn’s VPN, Salesforce data, the Qlik analytics platform, SAP’s business intelligence system, and SharePoint files.



Leave a Comment

Your email address will not be published. Required fields are marked *