

It comes just over a week after a hacking group targeted the University of Pennsylvania for its ‘vast, wonderfully wealthy donor database.’
Princeton University confirmed a data breach that affected its database with personal information about affiliates — including students, parents, alumni, and donors. The cyberattack comes just over a week after a hacking group targeted the University of Pennsylvania for its “vast, wonderfully wealthy donor database.”
“Our teams are working around the clock with outside experts and law enforcement to understand precisely what happened here and how it may affect your personal information,” Princeton University said.
Princeton University says a database containing information about “alumni, donors, some faculty, students, parents, and other members of the University community” was compromised by “outside actors” for less than a day. The university sent an email on Saturday, November 15, to individuals potentially affected by the cybersecurity breach. According to the email, the database “does not generally contain” information like Social Security numbers, passwords, or financial information such as credit card or bank account numbers. However, the database does contain personal information such as names, email addresses, phone numbers, home and business addresses, and donation histories.
“The database does not contain detailed student records covered by federal privacy laws or data about staff employees unless they are donors,” the university said in its email. (Emphasis added.)
Princeton said it does not know what information in the database was viewed or accessed, although it believes that no other university technology system was affected.
In its email, it warned individuals about “unusual messages” purporting to be sent from the university.
“No one from Princeton University should ever call, text, or email you asking for sensitive information such as Social Security numbers, passwords, or bank information,” said the school. “If you have any doubts about whether a communication you receive from Princeton University is legitimate, please verify its legitimacy with a known University person before clicking on any links or downloading any attachment.”
The incident at Princeton University occurred just over a week after a hacking group targeted the University of Pennsylvania for its donor base.
The security and technology publication Bleeping Computer reported that a hacking group breached the University of Pennsylvania’s systems on October 30th, and by the next day had downloaded sensitive information — such as net worth estimates, donation histories, dates of birth, addresses, phone numbers, and demographic details — associated with roughly 1.2 million students, alumni, and donors. The hacking group claims to have gained access to the data through a university employee’s “PennKey” account, which is used by affiliates of the university to authenticate their identity and use the university’s resources. Since the attack, the group has publicly shared a 1.7-GB archive containing spreadsheets, donation materials, and other files allegedly taken from UPenn. A hacker who claims to have participated in the attack on UPenn says the group will sell at least some of the data, per the Verge.
The hackers also took the opportunity to prank the university, sending out a crude, anti-woke email to roughly 700,000 affiliates. The following message was sent from an official University of Pennsylvania email account:
Dear Penn community,
The University of Pennsylvania is a dogsh** elitist institution full of woke retards. We have terrible security practices and are completely unmeritocratic. We hire and admit morons because we love legacies, donors, and unqualified affirmative action admits. We love breaking federal laws like FERPA (all your data will be leaked) and Supreme Court rulings like SFFA.
Please stop giving us money.
The University of Pennsylvania attempted to downplay the severity of the incident and released a statement referencing “fraudulent emails.” Although the university admitted its “incident response team” was addressing the issue, the statement seemingly suggested that the school’s concern was the content of the email — not a data compromise.
“All of the emails are incredibly offensive and in no way reflective of Penn or Penn GSE’s [Graduation School of Education] mission or values,” read a mass email to the university community. “We sincerely apologize for the harm this has caused and is causing. Over and above the inconvenience of getting your inboxes spammed, these emails are hurtful and upsetting.”
National Review previously reported that four alumni have filed a class action lawsuit against the University of Pennsylvania regarding the data breach.
Alumnus Kelli Mackey filed a class action lawsuit against the school on November 4 arguing that affiliates of the University of Pennsylvania whose personal information was obtained now face “imminent and substantial risk” of their data being misused, including in the form of spam electronic communication, unauthorized credit card charges, and unauthorized email access. Additional “harms” the university’s affiliates may face include targeted advertising without consent and the opening of fraudulent accounts by third parties.
Three alumni independently filed nearly identical class action lawsuits arguing that the university’s “unlawful conduct” includes failing to maintain adequate data security practices, failing to protect personally identifying information, failing to “properly monitor” its data systems, and failing to comply with FTC guidelines.