[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3vo3ubug827xo":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":12,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":40,"seoTitle":41,"seoDescription":42,"logoUrl":43,"isVerified":4,"isSensitive":44,"isSpamList":44,"isMalware":44,"company":45},"6a452308a20f867c8ba8e729","university-of-pennsylvania","University of Pennsylvania Data Breach","upenn.edu","2025-10-30T00:00:00.000Z","2026-02-16T21:57:51.000Z",null,"2026-07-03T09:42:41.116Z","2026-07-19T00:02:49.191Z","Third party breach","",[],623750,"known","unknown","en",[21,23],"tr",{"en":25,"tr":26},{"slug":7},{"slug":7},"High",[29,30,31,32,33,34,35,36,37,38,39],"Charitable donations","Dates of birth","Email addresses","Genders","Income levels","Job titles","Names","Physical addresses","Religions","Salutations","Spouses names","\u003Cp>The University of Pennsylvania data breach, which occurred in October 2025, was recorded as an incident that largely affected the university's donor database and later gained wide visibility with the release of the data in February 2026. The dataset, which contained approximately 624,000 unique email addresses, included fields such as names, physical addresses, birth dates, gender information, job titles, income level estimates, honorifics, spouse names, religious affiliation, and donation history. Therefore, the incident not only constitutes a leak of contact information but also poses a high risk in terms of donor profiling and personal privacy.\u003C\u002Fp> \u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2> \u003Cp>The types of data listed in this record are Charitable donations, Dates of birth, Email addresses, Genders, Income levels, Job titles, Names, Physical addresses, Religions, Salutations, and Spouses' names. These fields may not be equally filled for every user; some additional information may be present in smaller subsets. Nevertheless, listing fields such as donations, income, religion, and spouse's name increases the risk of targeted social engineering and impacts privacy.\u003C\u002Fp> \u003Ch2>Donor Database Context\u003C\u002Fh2> \u003Cp>University donor databases may include alumni, donors, families, institutional representatives, and individuals associated with the academic community. These relationships can be used for fake donation campaigns, event invitations, alumni association messages, scholarship fund notifications, or personalized communication. Contacting a person with their name, form of address, physical address, and donation history context may appear more trustworthy than an ordinary email.\u003C\u002Fp> \u003Ch2>Donation, Income and Privacy Effect\u003C\u002Fh2> \u003Cp>The fields of Charitable donations and Income levels may lead to inferences about financial status or donation capacity. This information is not precise financial account data; however, it can create a sufficient profile to target the user. Fake donation renewals, tax receipts, fund transfers, donation matching, or urgent campaign messages should be carefully evaluated in this context. Any communication requesting payment should be verified through an independent channel.\u003C\u002Fp> \u003Cp>The fields of Religions and Spouses' names are particularly sensitive in terms of privacy. These fields can make a person's family and belief context visible. It should not be assumed that every record contains these fields; however, for users for whom they are present, the risk of social pressure, targeted manipulation, or personalized fraud is higher. Therefore, the issue should not be addressed solely as an institutional communication or donation management problem.\u003C\u002Fp> \u003Ch2>Identity Verification and Social Engineering Risks\u003C\u002Fh2> \u003Cp>Fields such as dates of birth, physical addresses, and job titles increase the risk of identity verification and social engineering. A message reaching a donor or alumnus with the correct job title, address, and date of birth may appear like a notification from a fake university unit or donation office. Users should use the university's known channel instead of a link in requests to update profiles, confirm donations, register for events, for tax documents, or to verify personal information.\u003C\u002Fp> \u003Cp>From the perspective of institutions, this incident shows that donor databases contain sensitive personal data beyond being a marketing or relationship management tool. When donation history, income estimates, family and belief information are kept in the same record, the impact of a breach goes far beyond communication data. Data minimization, cleaning up old donor records, narrowing access limits, and separate protection of sensitive fields are critically important.\u003C\u002Fp> \u003Ch2>Necessary Precautions\u003C\u002Fh2> \u003Cp>Affected individuals should be cautious of donations, alumni events, tax documents, scholarship funds, profile updates, or personal information verification messages coming under the name University of Pennsylvania. Even if a message contains personal details, this is not proof of reliability. Requests for payment, documents, identity, or address updates should be verified directly through known university channels.\u003C\u002Fp> \u003Ch2>Long-Term Donor Profile Risk\u003C\u002Fh2> \u003Cp>This record shows how extensive a relationship map donor data can have in academic institutions. When a donor's relationship with the university, graduation history, donation tendency, family, and form of address come together, it becomes easier to tailor fake messages to the individual. Attackers can use this not only to ask for money, but also to gather more information under the pretext of updating data, event registration, or special invitations.\u003C\u002Fp> \u003Cp>Fields such as donation history and income level can be used to target a person based on their financial capacity. Fields like religion and spouse's name can be used in messages that may create emotional or social pressure. People affected should consider that if they receive a university communication that seems very personal, it could result from a data leak and should verify it through official, known channels rather than through the person or link in the message.\u003C\u002Fp>","University of Pennsylvania Data Breach (623.8 Thousand Reported Records)","University of Pennsylvania Data Breach. 623.8 Thousand reported records are reported. Reported data: Charitable donations, Dates of birth, Email addresses…","\u002Fuploads\u002Flogo\u002Fupenn_edu.webp",false,{"name":46,"sector":47,"country":48,"website":9,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":12},"University of Pennsylvania","Education","United States"]