News

UPenn Alumni Sue After Hackers Breach ‘Woke’ University’s Databases

Students walk between classes on the Locust Walk on the campus of the University of Pennsylvania in Philadelphia, Pa. (Charles Mostoller/Reuters)

The hackers released university records, bank transaction receipts, donor memos, and personally identifying information of students, alumni, and donors.

Sign in here to read more.

University of Pennsylvania alumni have filed several class action lawsuits against their alma mater over a data breach that led to the release of university records, bank transaction receipts, memos about donors and their families, and personally identifying information of students, alumni, and donors.

The hackers who targeted the university sent the following email from an official university account to roughly 700,000 students and alumni on October 31:

Dear Penn community,

The University of Pennsylvania is a dogsh** elitist institution full of woke retards. We have terrible security practices and are completely unmeritocratic. We hire and admit morons because we love legacies, donors, and unqualified affirmative action admits. We love breaking federal laws like FERPA (all your data will be leaked) and Supreme Court rulings like SFFA.

Please stop giving us money.

On the day of the attack, the university attempted to downplay the severity of the incident and released a statement referencing “fraudulent emails.”


“All of the emails are incredibly offensive and in no way reflective of Penn or Penn GSE’s [Graduation School of Education] mission or values,” read a mass email to the university community. “We sincerely apologize for the harm this has caused and is causing. Over and above the inconvenience of getting your inboxes spammed, these emails are hurtful and upsetting.”

The security and technology publication Bleeping Computer reported that the hacking group breached the University of Pennsylvania’s systems on October 30th, and by the following day had downloaded sensitive information — such as estimated net worth, donation history, dates of birth, addresses, phone numbers, and demographic details — lined to roughly 1.2 million students, alumni, and donors. The hacking group claims to have gained access to the data through a university employee’s “PennKey” account, which is used by affiliates of the university to authenticate their identity and use university’s resources. Since the attack, the group has publicly shared a 1.7-GB archive containing spreadsheets, donation materials, and other files allegedly taken from UPenn.

“While we’re not really politically motivated, we have no love for these nepobaby-serving institutions,” a hacker told Bleeping Computer. “The main goal was their vast, wonderfully wealthy donor database.”




A hacker who claims to have participated in the attack on UPenn says the group will sell at least some of the data, per the Verge.

“That email was certainly not the most eloquent communication ever written, and we’d have loved to go into more detail about the university’s hatred of merit and love of nepobabies and unqualified DEI picks, but time was extremely limited,” states a message on Leakforum from the individuals who claim to have committed the cyberattack.

Since the breach, several alumni have filed class action lawsuits against the university.

Kelli Mackey, who received a Masters of Science in Education from UPenn, filed a class action lawsuit against the school on November 4.

The lawsuit argues that affiliates of the University of Pennsylvania whose personal information was obtained now face “imminent and substantial risk” of their data being misused, including in the form of spam electronic communication, unauthorized credit card charges, and unauthorized email access. Additional “harms” the university’s affiliates may face include targeting advertising without consent and fraudulent accounts under their name.


“This is a class action for damages with respect to the University of Pennsylvania for its failure to protect the sensitive information of its students, alumni, and donors,” states the lawsuit. “Plaintiff has suffered imminent and impending injury arising from the substantially increased risk of fraud, identity theft, and misuse resulting from her PII, in combination with her name, being placed in the hands of unauthorized third parties/criminals.”

Three nearly identical class action lawsuits were independently filed by three alumni: Undergraduate alumnus Christopher Kelly, law school alumnus Mary Sikora, and undergraduate alumnus Christian Bersani. Kelly filed on November 3, while Sikora and Bersani filed on November 4.


All three plaintiffs argue that the University of Pennsylvania’s “unlawful conduct” includes “failing to maintain an adequate data security system to reduce the risk of data breaches and cyber-attacks,” failing to protect personally identifying information, “failing to properly monitor its own data security systems for existing intrusions,” “failing to ensure that its vendors with access to its computer systems and

data employed reasonable security procedures,” “failing to train its employees in the proper handling of emails containing Private Information and maintain adequate email security practices,” and “failing to comply with FTC guidelines for cybersecurity, in violation of Section 5 of the FTC Act.”

“It is estimated that UPenn’s annual revenue is over $15 billion per year,” states the lawsuits filed individually by Kelly, Sikora, and Bersani. “In other words, UPenn could have afforded to implement adequate data security prior to the Breach but deliberately chose not to.”


A University of Pennsylvania spokesperson said the university does not comment on pending litigation.

Exit mobile version