Ransomware victim disclosure
← All victimsUniversity of Pennsylvania
Claimed by Hunters International · listed 3 months ago
Status timeline
- Listed
Feb 24, 2026
- Data leaked
At a glance
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Feb 24, 2026
- Records
- 1.2M Records
About the victim
AI dossier — public-source company profileThe University of Pennsylvania (Penn) is a private Ivy League research university located in Philadelphia, Pennsylvania. Founded in 1740, it comprises 12 schools offering undergraduate, graduate, and professional degrees across arts, sciences, engineering, business, medicine, and law. It is one of the largest private employers in Philadelphia and enrolls approximately 28,000 students annually.
- Industry
- Higher Education
- Address
- 3451 Walnut Street, Philadelphia, PA 19104, United States
- Employees
- 10000+
- Founded
- 1740
Attack summary
Severity: critical — 1.2 million records exfiltrated from a major research university almost certainly encompasses regulated PII at scale (FERPA-protected student data, employee records, potentially medical/research data from affiliated health systems), and the data has been published, confirming exfiltration of sensitive data at critical scale.Hunters International claims to have exfiltrated 1.2 million records from the University of Pennsylvania, with data described as published following the victim's refusal to pay a ransom. The post indicates the data has been released as a consequence of non-payment.
Data the group says was taken
AI dossier — extracted from the leak post- Student records
- Personnel records
- Personal identifiable information (PII)
- Administrative data
What the group claims
Records: 1.2M Records | Updated: 04 Feb 2026 | Note: Make the right decision, don't be the next headline. | This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
