• November 7, 2025
  • thepulsetwentyfour@gmail.com
  • 0



  • Hackers accessed University systems via stolen SSO credentials, stealing data on 1.2 million individuals
  • Offensive mass email followed partial lockout; University later confirmed the breach was real
  • Attack exploited weak MFA enforcement among senior staff through social engineering

It seems the “obviously fake” and “fraudulent” claims recently made by the University of Pennsylvania hackers are not so “obviously fake” and “fraudulent”, after all – as the organization has now confirmed hackers stole files from its systems.

Cybercriminals recently revealed they had obtained “full access” to a University employee’s PennKey SSO account, which gave them access to its VPN, Salesforce data, Qlik analytics platform, SAP business intelligence system, and SharePoint files. Using that access, they stole data on approximately 1.2 million students, alumni, and donors.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *