Hackers publish personal information stolen during Harvard, UPenn data breaches
#ShinyHunters #Harvard University #University of Pennsylvania #Data Breach #Cybercrime #Extortion #Alumni Data #Social Engineering
📌 Key Takeaways
- ShinyHunters claimed responsibility for hacking Harvard and UPenn, publishing over one million records from each institution.
- The hackers initially sent emails to alumni from official university addresses, claiming political motives related to affirmative action.
- Both universities confirmed breaches in November 2023, attributing them to social engineering and voice phishing.
- The published data matches the types of information reported as stolen, including email addresses and donation details.
- UPenn is analyzing the data and will notify affected individuals if required by privacy regulations.
📖 Full Retelling
🐦 Character Reactions (Tweets)
Ivy League LeakerHarvard & UPenn alumni: Your data's out there. At least it's not as embarrassing as your college essays. #ShinyHunters #DataBreach
Cyber SleuthShinyHunters just outed more Ivy Leaguers than their parents did at graduation. #DataBreach #Harvard #UPenn
Phish SlayerHarvard & UPenn: 'We fell for a voice phishing scam.' Also Harvard: 'No comment.' #ShinyHunters #CyberSecurity
Data DivaShinyHunters just made Harvard & UPenn alumni the most connected people on the dark web. #DataBreach #CyberCrime
💬 Character Dialogue
🏷️ Themes
Cybercrime, Data Breach, Extortion, Education
📚 Related People & Topics
Cybercrime
Type of crime based in computer networks
Cybercrime encompasses a wide range of criminal activities that are carried out using digital devices and/or networks. It has been variously defined as "a crime committed on a computer network, especially the Internet; Cybercriminals may exploit vulnerabilities in computer systems and networks to g...
Harvard University
Private university in Cambridge, Massachusetts, US
Harvard University is a private Ivy League research university in Cambridge, Massachusetts, United States. Founded in 1636 as New College, and later named for its first benefactor, the Puritan clergyman John Harvard, it is the oldest institution of higher learning in the United States. Its influence...
ShinyHunters
Criminal internet hacker group
ShinyHunters is a notorious black-hat criminal hacker and extortion group that is believed to have formed in 2019, and is said to have been involved in a massively significant amount of data breaches. The group often extorts the company they've hacked, if the company does not pay the ransom the stol...
University of Pennsylvania
Private university in Philadelphia, US
The University of Pennsylvania (Penn or UPenn) is a private Ivy League research university in Philadelphia, Pennsylvania, United States. One of nine colonial colleges, it was chartered in 1755 through the efforts of founder and first president Benjamin Franklin, who had advocated for an educational ...
🔗 Entity Intersection Graph
Connections for Cybercrime:
- 👤 Anne Neuberger (1 shared articles)
- 👤 White House (1 shared articles)
- 🌐 Ransomware (1 shared articles)
- 👤 Cryptocurrency (1 shared articles)
- 🌐 Blockchain analysis (1 shared articles)
- 🌐 Bitcoin (1 shared articles)
- 🌐 Ransom (1 shared articles)
📄 Original Source Content
A notorious hacking group has claimed responsibility for last year’s data breaches at Harvard University and the University of Pennsylvania (UPenn) and published the data that they claim to have stolen from the two schools. On Wednesday, the group known as ShinyHunters published what it claims are more than one million records from each university on the group’s dedicated leak site, which the gang uses to extort its victims. In November, UPenn confirmed a data breach of “a select group of information systems related to Penn’s development and alumni activities.” At the time, the hackers also sent alumni emails announcing the hack from official university addresses . The university blamed the breach on social engineering , an attack that often relies on hackers impersonating someone and tricking them into doing something they would not normally do. In its official breach disclosure web page , which has since been taken offline, UPenn did not say exactly what type of data the hackers stole, simply saying the cybercriminals accessed “systems related to Penn’s development and alumni activities.” Contact Us Do you have more information about these breaches, or similar attacks? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or email . TechCrunch verified a portion of the data set by confirming with alumni and public records, such as matching the data against student ID numbers. Later in November, Harvard University also confirmed a breach on its alumni systems, blaming it on a voice phishing attack, meaning an attack where hackers tricked the targets into clicking on a link or opening an attachment with a voice call. Harvard said that the stolen data included email addresses, phone numbers, home and business addresses, event attendance, details of donations to the university, and other biographical information relating to the university’s fundraising and alumni en...