University of Pennsylvania confirms data stolen in cyberattack
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住关键信息。 文章主要讲宾夕法尼亚大学遭遇了网络攻击。黑客利用被窃取的员工账户,入侵了学校的发展和校友活动相关系统。他们窃取了大量数据,包括个人信息、财务信息和校友营销材料。攻击还导致发送了一封恶意邮件给70万收件人。学校已经通知FBI,并与 CrowdStrike 合作调查,同时加强了安全措施。 接下来,我需要把这些要点浓缩到100字以内。确保涵盖攻击方式、窃取的数据类型、影响范围以及学校的应对措施。 可能的结构是:宾夕法尼亚大学遭受网络攻击,黑客利用员工账户入侵系统,窃取大量数据并发送恶意邮件。学校已采取行动调查并加强安全。 检查一下字数是否在限制内,并确保信息准确无误。 </think> 宾夕法尼亚大学遭遇网络攻击,黑客利用员工账户入侵系统,窃取1.71GB内部文件及120万捐赠者数据,并发送恶意邮件。学校已通知FBI并加强安全措施。 2025-11-5 16:15:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:6 收藏

University of Pennsylvania

The University of Pennsylvania has confirmed that a hacker breached numerous internal systems related to the university's development and alumni activities and stole data in a cyberattack. 

In a new statement, Penn confirmed BleepingComputer's reporting that the hackers breached its systems using compromised credentials, stating they were stolen in a social engineering attack.

"On October 31, Penn discovered that a select group of information systems related to Penn's development and alumni activities had been compromised," reads a new Penn statement.

Wiz

"Penn employs a robust information security program; however, access to these systems occurred due to a sophisticated identity impersonation commonly known as social engineering."

"Penn's staff rapidly locked down the systems and prevented further unauthorized access; however, not before an offensive and fraudulent email was sent to our community and information was taken by the attacker. Penn is still investigating the nature of the information that was obtained during this time."

The University of Pennsylvania says it has notified the FBI of the breach and is working with CrowdStrike to investigate the security incident.

As first reported by BleepingComputer, the threat actor breached Penn's systems on October 30 using an employee's PennKey SSO account that provided access to the university's Salesforce instance, Qlik analytics platform, SAP business intelligence system, and SharePoint files.

Using this access, the threat actors stole 1.71 GB of internal documents from the university's SharePoint and Box storage platforms, including spreadsheets, documents, financial information, and alumni marketing materials.

The hackers also told BleepingComputer that they stole Penn's Salesforce donor marketing database, containing 1.2 million records with a wide variety of donor information.

A sample of this data includes 158 distinct fields, which contain the following sensitive information:

  • Personally Identifiable Information (PII): full name, birthdate, gender, home and mailing addresses, phone numbers, and email addresses.
  • Financial and donor data: gift histories, wealth ratings, and lifetime commitment amounts.
  • Employment and affiliation details: employer, job title, and academic affiliations.

After discovering their access had been revoked, the hacker said they still had access to Penn's Salesforce Marketing Cloud account and used it to send an offensive mass email to 700,000 recipients.

In a post on a hacking forum, the attackers say they are not currently leaking the data records but may do so in a month or two.

While the hackers claimed the attack wasn't politically motivated and said their goal was Penn's "vast, wonderfully wealthy donor database," both their emails and a post on a hacking forum were laced with sharp criticism of the university's alleged DEI practices, admissions policies, and "love of nepobabies."

The University of Pennsylvania says it is taking steps to increase security on its systems, including employee training on social engineering attacks and enhanced monitoring and security measures.

After the investigation is complete, Penn says it will notify those affected by the data breach.

The university is also warning Penn students and alumni to be wary of suspicious calls or emails that could be phishing attempts or social engineering attacks.

Wiz

The 2026 CISO Budget Benchmark

It's budget season! Over 300 CISOs and security leaders have shared how they're planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.

Learn how top leaders are turning investment into measurable impact.


文章来源: https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-confirms-data-stolen-in-cyberattack/
如有侵权请联系:admin#unsafe.sh