Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposurethird-party-vendor-breachbreach-disclosure-notificationeducation-sector-threat

University of Pennsylvania Email System Breach and Data Leak

Updated 3mo agoFirst seen Nov 6, 20252 sources

A hacker gained unauthorized access to the University of Pennsylvania's Salesforce Marketing Cloud mailing system, using it to send a mass email to approximately 700,000 recipients and mock the university's security and admissions practices. The attacker claimed to have exfiltrated sensitive data on 1.2 million donors, alumni, and students, including names, birthdates, addresses, contact information, estimated net worth, donation history, and demographic details such as religion, race, and sexual orientation. The university confirmed the breach originated from its connect.upenn.edu platform, which is hosted by Salesforce, and that the attacker was able to distribute the message widely before losing access on October 31.

Despite losing initial access, the attacker asserted continued control over the Salesforce Marketing Cloud system and subsequently published a 1.7-gigabyte archive allegedly containing the stolen data. The incident highlights significant risks associated with third-party cloud-based communication platforms and the potential for large-scale exposure of sensitive personal and financial information. The breach has raised concerns about the security of university systems and the protection of donor and student data, with the attacker openly ridiculing the institution's cybersecurity posture in the process.

Share:
University of Pennsylvania Email System Breach and Data Leak
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Nov 6, 20258mo ago

Cyderes reveals Advanced Installer supply chain risk

Cyderes researchers identified a supply chain weakness involving the Advanced Installer tool that could let attackers distribute malware through legitimate software updates when digital signature enforcement is not used.

Proofpoint reports remote-access-tool intrusions tied to cargo theft

Proofpoint said threat actors were using remote access tools to infiltrate logistics platforms and facilitate theft of trucking cargo.

FortiGuard uncovers TruffleNet BEC scam abusing AWS infrastructure

FortiGuard researchers reported the 'TruffleNet' business email compromise scheme, which used Amazon AWS infrastructure to support phishing operations.

Microsoft identifies SesameOp backdoor using OpenAI Assistants API

Microsoft disclosed the 'SesameOp' backdoor, describing how it abused the OpenAI Assistants API for covert command-and-control activity.

University of Pennsylvania email breach exposes 1.2 million people

A major breach at the University of Pennsylvania exposed sensitive data belonging to about 1.2 million donors, alumni, and students. The attacker used the university's Salesforce Marketing Cloud environment to send mocking emails and later leaked internal documents.

Ukrainian national extradited to the US over Conti ransomware role

Irish authorities extradited Ukrainian national Oleksii Lytvynenko to the United States for his alleged role in Conti ransomware operations.

Operation Ironside leads to 55 arrests and $17 million in seizures

Australian police announced a new round of Operation Ironside actions, arresting 55 people and seizing about $17 million in assets after exploiting the compromised Anom messaging app to infiltrate organized crime networks.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

25 LINKEDOpen in app
Threat actors
3 linked
Organizations
19 linked
SalesforceDell TechnologiesAmazonfbiAmazon Web ServicesAustralian Federal PoliceWordpressFortinetInformation Security Media GroupOpenaiAppleProofpointN-AbleMicrosoft CorporationAdobeContiCyderesCaphyonUniversity of Pennsylvania
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.