Ransomware victim disclosure
← All victimsUniversity of Pennsylvania
Claimed by Shinyhunters · listed 4 months ago
Status timeline
- ListedFeb 24, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Feb 24, 2026
- Records
- 1.2M Records
About the victim
AI dossier — public-source company profileThe University of Pennsylvania (Penn) is a private Ivy League research university located in Philadelphia, Pennsylvania. Founded in 1740, it comprises 12 schools offering undergraduate, graduate, and professional programs, and is affiliated with Penn Medicine, one of the leading academic medical centers in the United States. The university enrolls approximately 25,000 students and employs tens of thousands of faculty and staff.
- Industry
- Higher Education
- Address
- 3451 Walnut Street, Philadelphia, PA 19104, United States
- Employees
- 10001+
- Founded
- 1740
Attack summary
Severity: critical — 1.2 million records exfiltrated from a major Ivy League university with a large medical affiliate, strongly implying large-scale PII exposure of students, faculty, staff, and potentially patients; data has been published rather than merely threatened.ShinyHunters claims to have exfiltrated approximately 1.2 million records from the University of Pennsylvania, with the data having been published as of 4 February 2026 following what the group characterizes as a refusal to pay a ransom.
Data the group says was taken
AI dossier — extracted from the leak post- Personal records (1.2 million individuals)
- Potentially student/faculty/staff PII
- Potentially academic or administrative data
What the group claims
Records: 1.2M Records | Updated: 04 Feb 2026 | Note: Make the right decision, don't be the next headline. | This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

