The University of Pennsylvania experienced a cybersecurity incident in which offensive emails were sent to thousands of students and alumni from addresses associated with the Graduate School of Education. The emails, distributed via the university's mailing list platform hosted on Salesforce Marketing Cloud, contained inflammatory language, criticized the university's security and admissions practices, and threatened to leak stolen data. University officials confirmed the emails were fraudulent and stated that their Office of Information Security and Incident Response team were actively investigating the breach.
The emails referenced alleged violations of federal laws and Supreme Court rulings, echoing tactics seen in recent cyberattacks on other universities following the Supreme Court's decision on affirmative action. While the university has not confirmed whether any data was actually stolen, recipients were advised to disregard the messages and report any further suspicious communications. The incident highlights ongoing threats targeting higher education institutions, particularly those related to contentious policy issues and data security vulnerabilities.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
Additional coverage highlighted that the attacker’s messaging echoed recent university-targeted incidents focused on affirmative action and alleged noncompliance with the Supreme Court’s 2023 admissions ruling.
Penn later confirmed that a cyberattack resulted in data theft, moving the incident from an unverified threatening email campaign to a confirmed breach affecting university data.
Subsequent reporting indicated the alleged breach may have impacted almost 1.2 million individuals, marking a significant escalation in the scope of the incident.
Penn said the message was fake and did not reflect the university or Penn GSE, and its Office of Information Security and Incident Response began actively handling the incident. The university advised recipients to delete the email and report related suspicious messages.
Thousands of current and former University of Pennsylvania Graduate School of Education students received a fraudulent email sent through the school system containing offensive language and threats to leak allegedly stolen university data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.