More

    “We have terrible security practices” – University of Pennsylvania hackers say they’ve stolen over a million records in major cyberattack



    • Attacker accessed University systems via compromised SSO, stealing data on 1.2 million individuals
    • Offensive mass email sent post-ejection using retained access to Salesforce Marketing Cloud
    • Stolen data includes PII, financials, and demographics; attacker targets wealthy donors, no ransom planned

    Cybercriminals have claimed responsibility for the recent cyberattack on the University of Pennsylvania, claiming they stole data on approximately 1.2 million students, alumni, and donors.

    An unnamed threat actor told BleepingComputer they gained “full access” to a University employee’s PennKey SSO account, which gave them access to Penn’s VPN, Salesforce data, Qlik analytics platform, SAP business intelligence system, and SharePoint files.


    https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1920-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img