DisclosureLens
Social EngineeringEducationEducationPhishingStolen CredentialsCustomer Data InvolvedTargetedIdentity (basic)Government IDPIIMediumContained

The Trustees of the University of Pennsylvania

bd_b7916a3e57a1c19c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 30, 2023

Filed

Mar 1, 2023

To disclose

4 weeks

Affected

1state residents only

Confidence

65%
Full breach record for The Trustees of the University of Pennsylvania3 incidents on file

University of Pennsylvania notified affected individuals of a data security incident where an employee's email account was compromised via suspicious activity (likely phishing) between August 13, 2022, and October 24, 2022. Personal information including names, addresses, SSNs, phone numbers, and email addresses may have been exposed. The university engaged third-party experts, reset passwords, implemented safeguards, and offered 12 months of credit monitoring.

Incident timeline

undetected · 170 days
discovery → filing · 4 weeks / 30 days

Aug 13, 2022

Begins

Jan 30, 2023

Discovered

Mar 1, 2023

Filed

vs. sector median

3 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.