In October 2025, the University of Pennsylvania experienced a data breach after the cybercriminal group ShinyHunters infiltrated internal systems related to Penn's development and alumni activities. The breach was discovered on October 31, 2025, when mass spam emails were sent from University-affiliated email addresses. The University has stated it conducted a comprehensive review and is notifying affected individuals.
The exposed data types included donor contact information, donor records, email addresses, phone numbers, home and business addresses, event attendance records, donation details, biographical information, confidential internal University memos, and personal information of high-profile individuals. The estimated number of affected individuals has a wide range, with ShinyHunters claiming 1.2 million records were affected, while Penn stated in a court document that less than 10 people were impacted. The breach was attributed to social engineering and phishing attacks targeting systems like Salesforce and cloud-based CRM applications.
Details are still emerging regarding this incident, and additional information may become available as investigations proceed. Official notices to affected individuals may be delayed.