---
title: "University of Pennsylvania development and alumni systems incident"
description: "Evidence-backed account of University of Pennsylvania development and alumni systems incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/university-of-pennsylvania-development-alumni-systems-incident-2025"
markdown_url: "https://www.ally.security/incidents/university-of-pennsylvania-development-alumni-systems-incident-2025.md"
stix_url: "https://www.ally.security/incidents/university-of-pennsylvania-development-alumni-systems-incident-2025/stix.json"
---

# University of Pennsylvania development and alumni systems incident

Social-engineering-enabled access to Penn development and alumni systems, information theft, and an offensive fraudulent email. A verified HIBP corpus associated with the incident and largely concerning donor records.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Social-engineering-enabled access to [Penn](https://www.upenn.edu/) development and alumni systems, information theft, and an offensive fraudulent email. [2](#source-2)

## Impact

A verified HIBP corpus associated with the incident and largely concerning donor records. [1](#source-1)

Documented data types include:

- Names — Names listed by HIBP; no claim that every record contained a name. [1](#source-1)
- Contact information — Email and physical-address fields listed by HIBP; field presence can vary by record. [1](#source-1)
- Demographic information — Gender and religion fields described by HIBP for some or a small subset of donor records; no claim of uniform presence. [1](#source-1)
- Credit and income information — Estimated-income information described by HIBP for a small subset; HIBP also lists donation history, spouse names, salutations, and job titles outside this category. [1](#source-1)
- Dates of birth — Dates of birth present for some donor records according to HIBP. [1](#source-1)

A cited record reports 623,750 records (Unique email addresses in HIBP's verified corpus; not a Penn-confirmed affected-person, donor, alumni, student, account, or total-row count; as of 2026-02-16). [1](#source-1)

## Timeline

### October 31, 2025 — Discovery

Penn's discovery date; not the access-start date. HIBP separately assigns October 30 as its BreachDate. [2](#source-2)

### November 4, 2025 — Public disclosure

Date shown on Penn's follow-up message; it may not be the earliest community communication. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Penn said a select group of information systems related to development and alumni activities was compromised through sophisticated identity impersonation, commonly known as social engineering. [2](#source-2)

Penn said staff prevented further unauthorized access, but not before an offensive and fraudulent email was sent to its community and the attacker took information. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

HIBP marked the University of Pennsylvania incident record verified and not fabricated. Penn said all systems were restored and operational, it notified the FBI, and it was investigating with law enforcement and third-party cybersecurity professionals including CrowdStrike. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/university-of-pennsylvania-development-alumni-systems-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### University of Pennsylvania breach record

advisory · Have I Been Pwned · Feb 16, 2026

<https://haveibeenpwned.com/api/v3/breach/UniversityOfPennsylvania>

<a id="source-2"></a>

### From the Vice President of Information Technology: A Message to the University—Follow Up to the Cybersecurity Incident

official · University of Pennsylvania Almanac · Nov 4, 2025

<https://almanac.upenn.edu/articles/from-the-vice-president-of-information-technology-a-message-to-the-university-follow-up-to-the-cybersecurity-incident>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Organization · 100% confidence · current**  
   October 2025 Penn development and alumni systems incident: University of Pennsylvania
2. **Resulted In · 90% confidence · current**  
   October 2025 Penn development and alumni systems incident: Penn donor and alumni data corpus
3. **Exposed Data Category · 90% confidence · current**  
   Penn donor and alumni data corpus: Names
4. **Resulted In · 100% confidence · current**  
   October 2025 Penn development and alumni systems incident: Penn said a select group of information systems related to development and alumni activities was compromised through sophisticated identity impersonation, commonly known as social engineering.
5. **Disclosed At · 100% confidence · current**  
   October 2025 Penn development and alumni systems incident: 2025-11-04
6. **Resulted In · 100% confidence · current**  
   Penn donor and alumni data corpus: HIBP marked the University of Pennsylvania breach record verified and not fabricated.
7. **Exposed Data Category · 90% confidence · current**  
   Penn donor and alumni data corpus: Contact information
8. **Discovered At · 100% confidence · current**  
   October 2025 Penn development and alumni systems incident: 2025-10-31
9. **Exposed Record Count · 100% confidence · current**  
   Penn donor and alumni data corpus: 623,750 record
10. **Resulted In · 100% confidence · current**  
   October 2025 Penn development and alumni systems incident: Penn said all systems were restored and operational, it notified the FBI, and it was investigating with law enforcement and third-party cybersecurity professionals including CrowdStrike.
11. **Resulted In · 100% confidence · current**  
   October 2025 Penn development and alumni systems incident: Penn said staff prevented further unauthorized access, but not before an offensive and fraudulent email was sent to its community and the attacker took information.
12. **Exposed Data Category · 85% confidence · current**  
   Penn donor and alumni data corpus: Demographic information
13. **Exposed Data Category · 85% confidence · current**  
   Penn donor and alumni data corpus: Credit and income information
14. **Exposed Data Category · 90% confidence · current**  
   Penn donor and alumni data corpus: Dates of birth

</details>
