A hacker has taken responsibility for last week's University of Pennsylvania "We got hacked" email incident, saying it was a far more extensive breach that exposed data on 1.2 million donors and internal documents. On Friday, University of Pennsylvania alumni and students began receiving multiple offensive emails from Penn.edu addresses claiming the university had been hacked and data stolen. "The University of Pennsylvania is a dog**** elitist institution full of woke retards. We have terrible security practices and are completely unmeritocratic," reads the email sent to Penn alumni and students. "We hire and admit morons because we love legacies, donors, and unqualified affirmative action admits. We love breaking federal laws like FERPA (all your data will be leaked) and Supreme Court rulings like SFFA." BleepingComputer confirmed the emails originated from connect.upenn.edu, a Penn mailing list platform hosted on Salesforce Marketing Cloud. The university downplayed the incident, describing the messages as "fraudulent emails" that were "obviously fake." However, the threat actor behind the attack contacted BleepingComputer, claiming the intrusion was far broader and that they had gained access to multiple university systems. The hacker said their group "gained full access" to an employee's PennKey SSO account, allowing access to Penn's VPN, Salesforce data, Qlik analytics platform, SAP business intelligence system, and SharePoint files. They said they exfiltrated data for...
Penn hacker claims to have stolen 1.2 million donor records in data breach
BleepingComputer
·Lawrence Abrams
·Published Nov 2, 2025
·Updated
Affected Software
1 affected component
Salesforce Marketing Cloud
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a hacker claiming responsibility for a significant data breach at the University of Pennsylvania, involving the theft of 1.2 million donor records.
2
What security implications are discussed?
The breach highlights vulnerabilities in managing donor information and the potential for identity theft and misuse of sensitive data.
3
What products or software are affected?
The breach primarily affects Salesforce Marketing Cloud, which may have been used to manage donor communications.
4
How did the breach occur at the University of Pennsylvania?
The details of the breach mechanism are not specified, but it involved unauthorized access to donor records and internal documents.
5
What actions are being taken following the data breach?
The university is likely investigating the breach and may implement enhanced security measures to protect donor information moving forward.