The Trustees of the University of Pennsylvania
ent_019dee4c6644739fc65d05d2bfdbf7de
Disclosures
21
State AG · Leak Site · 16 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
442,500
nationwide · State AG TX
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- The Trustees of the University of Pennsylvania
- Normalized
- the trustees of the university of pennsylvania— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300FG60YK9HZ7DS75
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (21)newest first
- Washington State AGas victim2026-04-15
The University of Pennsylvania reported a cyberattack on Oct 31, 2025, involving unauthorized access via a user account. Files containing contact and demographic info of alumni, donors, students, and employees were downloaded. 5,878 Washington residents were notified. Law enforcement was notified and an investigation launched.
- GLOBALLeak Siteas victim2026-02-04
Records: 1.2M Records | Updated: 04 Feb 2026 | Note: Make the right decision, don't be the next headline. | This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you.
- Oregon State AGas victim2025-12-22
University of Pennsylvania reported a data breach to the Oregon Attorney General. The breach was reported on 2025-12-22. The breach occurred during 11/11/2025. The breach was discovered on 11/11/2025. 2,722 individuals were affected. Notice was sent on 12/1/2025.
- New Hampshire State AGas victim2025-12-04
University of Pennsylvania notified NH AG of a security incident involving Oracle E-Business Suite. A previously unknown vulnerability allowed unauthorized access to financial application data. 1,588 NH residents affected; data included names, addresses, SSNs, and banking info. Notification began Dec 1, 2025, offering 24 months credit monitoring. No evidence of misuse. Law enforcement notified.
- Texas State AGas victim2025-12-03
The University of Pennsylvania based in Philadelphia, Pennsylvania, a educational institution entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-11-11 and reported on 2025-12-03. 11,455 Texas residents were affected. 442,500 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Financial Information (e.g. account number, credit or debit card number). Consumers were notified via U.S. Mail.
- Massachusetts State AGas victim2025-12-02
The University of Pennsylvania reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-12-02. 16,963 Massachusetts residents were affected.
- California State AGas victim2025-12-01
The University of Pennsylvania notified California residents of a data breach involving a third-party Oracle E-Business Suite application. A previously unknown vulnerability (zero-day) in Oracle software allowed unauthorized access to data between August 9 and August 11, 2025. Affected data included Social Security numbers, names, addresses, and bank account information. The University engaged cybersecurity experts, notified law enforcement, applied patches, and is offering 24 months of credit monitoring.
- Montana State AGas victim2025-12-01
University of Pennsylvania notified affected individuals of a data security incident involving its third-party Oracle E-Business Suite application. The incident stemmed from a previously unknown vulnerability (zero-day) in Oracle EBS, leading to unauthorized access and exfiltration of personal information. Penn engaged forensic experts, notified law enforcement, applied security patches, and offered 24 months of credit monitoring. No evidence of misuse was found at the time of notification.
- Iowa State AGas victim2025-12-01
University of Pennsylvania notified Iowa AG of a security incident involving its third-party Oracle E-Business Suite. A previously unknown vulnerability allowed unauthorized access to data belonging to 752 Iowa residents, exposing names, addresses, SSNs, and banking info. Penn discovered the breach on Nov 11, 2025, notified law enforcement, applied patches, and began notifying residents on Dec 1, 2025, offering 24 months of credit monitoring.
- South Carolina State AGas victim2025-12-01
The University of Pennsylvania notified South Carolina residents of a data security incident involving its third-party Oracle E-Business Suite application. The incident involved a previously unknown security vulnerability (exploit) that allowed unauthorized access to data. Personal information, including names and Social Security numbers, was obtained. Penn launched an investigation, notified law enforcement, applied security patches, and is offering 24 months of complimentary credit monitoring.
- Delaware State AGas victim2025-12-01
The University of Pennsylvania notified affected individuals of a data security incident involving its third-party Oracle E-Business Suite (EBS) application. The incident involved a previously unknown security vulnerability (zero-day/n-day) exploited by an external actor to gain unauthorized access and exfiltrate personal information, including government-issued identifiers and basic PII. Penn discovered the unauthorized access on November 11, 2025, and notified law enforcement. No evidence of misuse was found at the time of notification. Remediation included applying Oracle security patches, reinforcing systems, and offering 24 months of complimentary credit monitoring via Experian.
- Nebraska State AGas victim2025-12-01
The University of Pennsylvania notified affected individuals of a data security incident involving its third-party Oracle E-Business Suite (EBS). A previously unknown vulnerability (zero-day) in Oracle EBS allowed unauthorized access and data exfiltration. Penn discovered the unauthorized access on November 11, 2025, and sent notification letters on December 1, 2025. Affected data included government-issued identifiers and personal information. Penn engaged forensic experts, notified law enforcement, applied security patches, and offered 24 months of complimentary credit monitoring.
- Illinois State AGas victim2025-12-01
THE UNIVERSITY OF PENNSYLVANIA filed a data-breach notice with the Illinois Attorney General in December 2025 (case 25-12-626). The register records the breach as discovered on November 11, 2025. Personal information types reported: financial account number, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Maine State AGas victim2025-12-01
The University of Pennsylvania disclosed a data breach affecting Oracle E-Business Suite. Unauthorized access occurred between August 9-11, 2025, discovered on November 11, 2025. 1,488 Maine residents were notified on December 1, 2025. Personal information was accessed. The University engaged forensic experts, notified law enforcement, and applied security patches. Credit monitoring services were offered.
- Indiana State AGas victim2025-12-01
The University of Pennsylvania reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-09 and was reported on 2025-12-01. 2,067 Indiana residents were affected.
- Washington State AGas victim2025-12-01
The University of Pennsylvania disclosed a data breach involving its Oracle E-Business Suite application. Unauthorized access occurred between August 9-11, 2025, exploiting a previously unknown vulnerability. The incident affected 6,413 Washington residents, with personal information including names and government IDs accessed. Penn notified law enforcement, applied security patches, and offered 24 months of credit monitoring.
- Vermont State AGas victim2025-12-01
The University of Pennsylvania notified consumers of a data security incident involving its third-party Oracle E-Business Suite application. A previously unknown security vulnerability allowed unauthorized access to data. The incident involved personal information including names and Social Security numbers. Penn engaged cybersecurity experts, notified law enforcement, applied security patches, and offered 24 months of complimentary credit monitoring.
- Massachusetts State AGas victim2024-05-24
University of Pennsylvania reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-05-24. 5 Massachusetts residents were affected.
- Maine State AGas victim2024-05-24
University of Pennsylvania reported a third-party vendor breach on 10/29/2023, discovered 03/22/2024, affecting 388 individuals (1 in Maine). Compromised data included names and Social Security Numbers. The university notified affected individuals in writing on 04/09/2024 and provided 24 months of credit monitoring via Experian.
- Indiana State AGas victim2024-04-09
University of Pennsylvania reported a data breach to the Indiana Attorney General. The breach occurred on 2023-10-29 and was reported on 2024-04-09. 3 Indiana residents were affected. 388 individuals affected in total.
- Montana State AGas victim2023-03-01
University of Pennsylvania notified affected individuals of a data security incident where an employee's email account was compromised via suspicious activity (likely phishing) between August 13, 2022, and October 24, 2022. Personal information including names, addresses, SSNs, phone numbers, and email addresses may have been exposed. The university engaged third-party experts, reset passwords, implemented safeguards, and offered 12 months of credit monitoring.