United States
The University of Pennsylvania
The University of Pennsylvania confirmed a massive data breach on November 5, which exposed the personal information of students, alumni, staff and community affiliates. The breach reportedly exposed more than 1.2 million records.
The cyber incident came to light on October 31, when several members of the Penn community received emails claiming to be from the university's Graduate School of Education (GSE). The university later confirmed that certain systems linked to its development and alumni activities had been compromised. The stolen data includes personally identifiable information (PII) — some of which dates back decades — along with banking details. However, the university said that no medical information was involved in the breach.
According to Penn, the attack began with a social engineering scam. After learning of the incident, university staff quickly locked down the affected systems but were unable to prevent the fraudulent emails from being sent or the sensitive information from being stolen.
How it could affect your business
Reports suggest that the lack of multifactor authentication (MFA) on some accounts may have given the attacker an entry point in this breach. This highlights the importance of enforcing MFA across all user accounts and implementing stricter access controls. These simple but critical measures can greatly reduce the risk of unauthorized access and limit the damage from social engineering attacks.
