University of Pennsylvania development and alumni systems incident

Social-engineering-enabled access to Penn development and alumni systems, information theft, and an offensive fraudulent email. A verified HIBP corpus associated with the incident and largely concerning donor records.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Social-engineering-enabled access to Penn development and alumni systems, information theft, and an offensive fraudulent email. [2]

Impact

A verified HIBP corpus associated with the incident and largely concerning donor records. [1]

Documented data types include:

  • Names — Names listed by HIBP; no claim that every record contained a name. [1]
  • Contact information — Email and physical-address fields listed by HIBP; field presence can vary by record. [1]
  • Demographic information — Gender and religion fields described by HIBP for some or a small subset of donor records; no claim of uniform presence. [1]
  • Credit and income information — Estimated-income information described by HIBP for a small subset; HIBP also lists donation history, spouse names, salutations, and job titles outside this category. [1]
  • Dates of birth — Dates of birth present for some donor records according to HIBP. [1]

A cited record reports 623,750 records (Unique email addresses in HIBP’s verified corpus; not a Penn-confirmed affected-person, donor, alumni, student, account, or total-row count; as of 2026-02-16). [1]

Timeline

  1. Discovery

    Penn’s discovery date; not the access-start date. HIBP separately assigns October 30 as its BreachDate.

    [2]
  2. Public disclosure

    Date shown on Penn’s follow-up message; it may not be the earliest community communication.

    [2]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Penn said a select group of information systems related to development and alumni activities was compromised through sophisticated identity impersonation, commonly known as social engineering. [2]

Penn said staff prevented further unauthorized access, but not before an offensive and fraudulent email was sent to its community and the attacker took information. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

HIBP marked the University of Pennsylvania incident record verified and not fabricated. Penn said all systems were restored and operational, it notified the FBI, and it was investigating with law enforcement and third-party cybersecurity professionals including CrowdStrike. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]