
The University of Pennsylvania has concluded its investigation into a cybersecurity breach discovered in late October 2025 that reportedly exposed personal data belonging to more than 1.2 million students, alumni, and donors, university officials confirmed.
A University spokesperson said Penn completed a comprehensive review of the Oct. 31 incident and has notified affected individuals in compliance with applicable notification laws. The University’s webpage dedicated to the breach, which previously provided guidance to the Penn community, is no longer accessible and now returns a 404 error.
“Penn conducted a comprehensive review of the downloaded files to determine whose information may have been involved. That review is now complete,” the spokesperson said. “Penn sent notifications to the limited number of individuals whose personal information was impacted as required by applicable notification laws.”
The spokesperson added that the notifications included resources for individuals who may have questions or concerns related to the incident.
Earlier disclosures on the University’s breach webpage stated that the volume of data obtained by the attackers had been mischaracterized in public reports. While the University advised community members to take steps to safeguard their personal information, it also said there was no evidence that the exposed data had been used for fraudulent purposes.
The breach has led to legal action against the University. Since the incident, 18 Penn graduates filed class-action lawsuits alleging that the University failed to adequately protect sensitive information and that the breach caused greater harm than acknowledged. A federal district judge later consolidated the individual filings. In recent weeks, seven of the original lawsuits have been withdrawn.
A University spokesperson declined to comment further on the matter, citing ongoing litigation.
The breach first drew attention after mass emails were sent to the Penn community from multiple University-affiliated email accounts. Two days later, the individuals claiming responsibility said they had accessed Penn’s systems and downloaded data that included donor history, estimated donor net worth, and demographic details.
On Nov. 1, thousands of internal University files were posted to an online forum. The released material included internal communications and personal identifying information related to University donors and members of their families.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543