Clustered 5 filings across 5 jurisdictions · filing window Dec 1, 2025 → Dec 4, 2025. View entity profile → Other incidents for this victim →
incident inc_9f1e9cbf120c4ee7 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
DE IN ME NH VT
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Aug 9, 2025 → Aug 11, 2025
When the intrusion reportedly occurred, per the linked filings
Nov 11, 2025
Reported by DELAWARE AG, MAINE AG, VERMONT AG, NEW HAMPSHIRE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
The University of Pennsylvania notified affected individuals of a data security incident involving its third-party Oracle E-Business Suite (EBS) application. The incident involved a previously unknown security vulnerability (zero-day/n-day) exploited by an external actor to gain unauthorized access and exfiltrate personal information, including government-issued identifiers and basic PII. Penn discovered the unauthorized access on November 11, 2025, and notified law enforcement. No evidence of misuse was found at the time of notification. Remediation included applying Oracle security patches, reinforcing systems, and offering 24 months of complimentary credit monitoring via Experian.
The University of Pennsylvania reported a data breach impacting 1,488 Maine residents. The incident was identified as an external system breach or hacking event that occurred from August 9 to August 11, 2025. The breach was discovered on November 11, 2025. In response, the university is offering 24 months of complimentary credit monitoring and remediation services through Experian.
Affected (this filing): 1,488
The University of Pennsylvania reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-09 and was reported on 2025-12-01. 2,067 Indiana residents were affected.
Affected (this filing): 2,067
The University of Pennsylvania notified consumers of a data security incident involving its third-party Oracle E-Business Suite application. A previously unknown security vulnerability allowed unauthorized access to data. The incident involved personal information including names and Social Security numbers. Penn engaged cybersecurity experts, notified law enforcement, applied security patches, and offered 24 months of complimentary credit monitoring.
University of Pennsylvania notified NH AG of a security incident involving Oracle E-Business Suite. A previously unknown vulnerability allowed unauthorized access to financial application data. 1,588 NH residents affected; data included names, addresses, SSNs, and banking info. Notification began Dec 1, 2025, offering 24 months credit monitoring. No evidence of misuse. Law enforcement notified.
Affected (this filing): 1,588