The Trustees of the University of Pennsylvania
bd_194bd163b527a335 · schema v1 · pii pii-v1
Full breach record for The Trustees of the University of Pennsylvania →3 incidents on fileThe University of Pennsylvania notified California residents of a data breach involving a third-party Oracle E-Business Suite application. A previously unknown vulnerability (zero-day) in Oracle software allowed unauthorized access to data between August 9 and August 11, 2025. Affected data included Social Security numbers, names, addresses, and bank account information. The University engaged cybersecurity experts, notified law enforcement, applied patches, and is offering 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 9, 2025
Begins
Dec 1, 2025
Filed
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteshinyhuntersbd_20d98f86cadb16022026-02-04 · +65dVerified by operator
Regulatory filings (9) · sorted by filing gap
- Montana State AGbd_1fae715254418c002025-12-01Verified by operator
- Iowa State AGbd_3340eceed80aa4a62025-12-01Verified by operator
- South Carolina State AGbd_36bdda19f39a3c942025-12-01Verified
- Delaware State AGbd_5e138ad76c39ef7a2025-12-01Verified by operator
Show 5 more filings ↓Show fewer ↑up to 135d gap
- Massachusetts State AGbd_8ad1850d7141bc9a2025-12-02 · +1dVerified by operator
- Texas State AGbd_e679c6a24510eaf92025-12-03 · +2dVerified by operator
- New Hampshire State AGbd_04392877ff003a222025-12-04 · +3dVerified
- Oregon State AGbd_52860701b7a833ff2025-12-22 · +21dVerified by operator
- Washington State AGbd_5fa5e741d0d862242026-04-15 · +135dVerified by operator
Showing first 10 of 16 linked disclosures.
Filing propagation · 10 filings · 10 states
View merged incident ↗Pattern: first filing Dec 1 (MT), last Apr 15 (WA) — a 135-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 16 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.