A hacker gained unauthorized access to the University of Pennsylvania's Salesforce Marketing Cloud mailing system, using it to send a mass email to approximately 700,000 recipients and mock the university's security and admissions practices. The attacker claimed to have exfiltrated sensitive data on 1.2 million donors, alumni, and students, including names, birthdates, addresses, contact information, estimated net worth, donation history, and demographic details such as religion, race, and sexual orientation. The university confirmed the breach originated from its connect.upenn.edu platform, which is hosted by Salesforce, and that the attacker was able to distribute the message widely before losing access on October 31.
Despite losing initial access, the attacker asserted continued control over the Salesforce Marketing Cloud system and subsequently published a 1.7-gigabyte archive allegedly containing the stolen data. The incident highlights significant risks associated with third-party cloud-based communication platforms and the potential for large-scale exposure of sensitive personal and financial information. The breach has raised concerns about the security of university systems and the protection of donor and student data, with the attacker openly ridiculing the institution's cybersecurity posture in the process.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
Cyderes researchers identified a supply chain weakness involving the Advanced Installer tool that could let attackers distribute malware through legitimate software updates when digital signature enforcement is not used.
Proofpoint said threat actors were using remote access tools to infiltrate logistics platforms and facilitate theft of trucking cargo.
FortiGuard researchers reported the 'TruffleNet' business email compromise scheme, which used Amazon AWS infrastructure to support phishing operations.
Microsoft disclosed the 'SesameOp' backdoor, describing how it abused the OpenAI Assistants API for covert command-and-control activity.
A major breach at the University of Pennsylvania exposed sensitive data belonging to about 1.2 million donors, alumni, and students. The attacker used the university's Salesforce Marketing Cloud environment to send mocking emails and later leaked internal documents.
Irish authorities extradited Ukrainian national Oleksii Lytvynenko to the United States for his alleged role in Conti ransomware operations.
Australian police announced a new round of Operation Ironside actions, arresting 55 people and seizing about $17 million in assets after exploiting the compromised Anom messaging app to infiltrate organized crime networks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.