The Trustees of the University of Pennsylvania
bd_5e138ad76c39ef7a · schema v1 · pii pii-v1
Full breach record for The Trustees of the University of Pennsylvania →The University of Pennsylvania notified affected individuals of a data security incident involving its third-party Oracle E-Business Suite (EBS) application. The incident involved a previously unknown security vulnerability (zero-day/n-day) exploited by an external actor to gain unauthorized access and exfiltrate personal information, including government-issued identifiers and basic PII. Penn discovered the unauthorized access on November 11, 2025, and notified law enforcement. No evidence of misuse was found at the time of notification. Remediation included applying Oracle security patches, reinforcing systems, and offering 24 months of complimentary credit monitoring via Experian.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_9291855aaa6200eaMaine State AGfiled 2025-12-01Candidate
- bd_bc253bb47a7df0e4Indiana State AGfiled 2025-12-01Verified
- bd_f9886ce463a596c3Vermont State AGfiled 2025-12-01Verified
- bd_04392877ff003a22New Hampshire State AGfiled 2025-12-04(3d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2026/01/Penn-Consumer-Notice-Template-Proof-Redacted.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 1, 2025
- Raw hash
- 9bd834f840d0fc17cdfb5e1a8ae2d1ef438a5b2b6403459da8987f1770f93def
Reporting entity
- Name
- The Trustees of the University of Pennsylvanianorm: the trustees of the university of pennsylvania
Victim entity
- Name
- The Trustees of the University of Pennsylvanianorm: the trustees of the university of pennsylvania
Incident
- Discovered
- Nov 11, 2025
- Materiality determined
- —
- Notification sent
- Dec 1, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Cooperating with an ongoing federal law enforcement investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.