HackingVulnerability ExploitN-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The Trustees of the University of Pennsylvania
bd_f9886ce463a596c3 · schema v1 · pii pii-v1
Full breach record for The Trustees of the University of Pennsylvania →The University of Pennsylvania notified consumers of a data security incident involving its third-party Oracle E-Business Suite application. A previously unknown security vulnerability allowed unauthorized access to data. The incident involved personal information including names and Social Security numbers. Penn engaged cybersecurity experts, notified law enforcement, applied security patches, and offered 24 months of complimentary credit monitoring.
Vermont clock✓ VT AG ≤14 bday20 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_5e138ad76c39ef7aDelaware State AGfiled 2025-12-01Verified
- bd_9291855aaa6200eaMaine State AGfiled 2025-12-01Candidate
- bd_bc253bb47a7df0e4Indiana State AGfiled 2025-12-01Verified
- bd_04392877ff003a22New Hampshire State AGfiled 2025-12-04(3d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-01-university-pennsylvania-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 1, 2025
- Raw hash
- 07ed0877d7264bac7c966eb6a01a7f8bac29a48849db1a304b98fe07b52dc63c
Reporting entity
- Name
- The Trustees of the University of Pennsylvanianorm: the trustees of the university of pennsylvania
Victim entity
- Name
- The Trustees of the University of Pennsylvanianorm: the trustees of the university of pennsylvania
Incident
- Discovered
- Nov 11, 2025
- Materiality determined
- —
- Notification sent
- Dec 1, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- cooperating with an ongoing federal law enforcement investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.