Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
A verified HIBP corpus associated with the incident and largely concerning donor records. [1]
Documented data types include:
- Names — Names listed by HIBP; no claim that every record contained a name. [1]
- Contact information — Email and physical-address fields listed by HIBP; field presence can vary by record. [1]
- Demographic information — Gender and religion fields described by HIBP for some or a small subset of donor records; no claim of uniform presence. [1]
- Credit and income information — Estimated-income information described by HIBP for a small subset; HIBP also lists donation history, spouse names, salutations, and job titles outside this category. [1]
- Dates of birth — Dates of birth present for some donor records according to HIBP. [1]
A cited record reports 623,750 records (Unique email addresses in HIBP’s verified corpus; not a Penn-confirmed affected-person, donor, alumni, student, account, or total-row count; as of 2026-02-16). [1]
Timeline
Discovery
Penn’s discovery date; not the access-start date. HIBP separately assigns October 30 as its BreachDate.
[2]Public disclosure
Date shown on Penn’s follow-up message; it may not be the earliest community communication.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Penn said a select group of information systems related to development and alumni activities was compromised through sophisticated identity impersonation, commonly known as social engineering. [2]
Penn said staff prevented further unauthorized access, but not before an offensive and fraudulent email was sent to its community and the attacker took information. [2]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
HIBP marked the University of Pennsylvania incident record verified and not fabricated. Penn said all systems were restored and operational, it notified the FBI, and it was investigating with law enforcement and third-party cybersecurity professionals including CrowdStrike. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]
