Skip to main content
Back to overview
Medium

University of Pennsylvania Data Breach

The University of Pennsylvania experienced a cyberattack where threat actors breached its systems on October 30, 2025, using a compromised employee PennKey SSO account.

Key points

  • Breach occurred on October 30, 2025, discovered October 31, 2025.
  • Compromised employee PennKey SSO account used for initial access.
  • Accessed Salesforce, Qlik, SAP, and SharePoint systems.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Internal actor · Confidentiality impact

Possible insider activity

03

Potential impact

Potential data exposure

Confidentiality

Published
Oct 30, 2025
Updated
Jun 25, 2026
Confidence
Medium
Evidence
6 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Possible insider activity

Watch exposure paths that could affect data, operations or third-party trust.

  • Source type: possible insider or internal misuse

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

UpennData DisclosureUniversity of Pennsylvania Data BreachThe University of PennsylvaniaPennKey SSOSalesforceQlikSAPSharePointThey

Quick context

Questions about this signal

What happened in this signal?

The University of Pennsylvania experienced a cyberattack where threat actors breached its systems on October 30, 2025, using a compromised employee PennKey SSO account. The attackers gained access to systems related to the university's development and alumni activities, including Salesforce, Qlik analytics, SAP business intelligence, and SharePoint files. They stole 1.71 GB of internal documents and claimed to have accessed 1.2 million records from the Salesforce donor marketing database, containing PII such as names, birthdates, addresses, phone numbers, and financial information. The breach was discovered on October 31, 2025.

When was this signal reported?

Shadow Tier lists Oct 30, 2025 as the signal date.

Which organization is connected to this signal?

Upenn is the organization connected to this public signal.

Explore Upenn