More

    University of Pennsylvania confirms recent cyberattack led to major data theft



    • Hackers accessed University systems via stolen SSO credentials, stealing data on 1.2 million individuals
    • Offensive mass email followed partial lockout; University later confirmed the breach was real
    • Attack exploited weak MFA enforcement among senior staff through social engineering

    It seems the “obviously fake” and “fraudulent” claims recently made by the University of Pennsylvania hackers are not so “obviously fake” and “fraudulent”, after all – as the organization has now confirmed hackers stole files from its systems.

    Cybercriminals recently revealed they had obtained “full access” to a University employee’s PennKey SSO account, which gave them access to its VPN, Salesforce data, Qlik analytics platform, SAP business intelligence system, and SharePoint files. Using that access, they stole data on approximately 1.2 million students, alumni, and donors.


    https://cdn.mos.cms.futurecdn.net/VuBMgidwKAh2uEAV7UMikB-2560-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img