Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Penn Arts & Sciences

Penn Arts & Sciences Vendor Cyber Rating & Cyber Score

upenn.edu

The School of Arts and Sciences (SAS) forms the foundation of the scholarly excellence that has established Penn as one of the world's leading research universities. We teach students across all 12 Penn schools, and our academic departments span the reach from anthropology and biology to sociology and South Asian studies. The three educational divisions of SAS fulfill different missions, united by the School's broader commitment to providing its students with an unrivaled education in the arts and sciences. The College of Arts and Sciences is the academic home of the majority of Penn undergraduates and provides 60 percent of the courses taken by students in Penn's undergraduate professional schools. The Graduate Division offers doctoral


PAS A.I CyberSecurity Scoring

PAS
Company Information
Website:https://www.sas.upenn.edu
Employees number:56
Number of followers:3,296
NAICS:6113
Industry Type:Higher Education
Homepage:upenn.edu
PAS Risk Score (AI oriented)
Between 0 and 549
logo
PASHigher Education
Updated:
01/04/2026
433/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
PAS Global Score (TPRM)
xxxx
logo
PASHigher Education
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

PASCritical
Current Score
433C (CRITICAL)
01000
5 incidents
-93 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
465Before Incident
AUGUST 2026
459Before Incident
JULY 2026
457Before Incident
JUNE 2026
451Before Incident
MAY 2026
440Before Incident
APRIL 2026
435Before Incident
MARCH 2026
433Before Incident
FEBRUARY 2026
427Before Incident
JANUARY 2026
421Before Incident
DECEMBER 2025
410Before Incident
NOVEMBER 2025
495Before Incident
Breach
06 Nov 2025PAS
University of Pennsylvania (Penn)

University of Pennsylvania Email Hack and Data Breach (2025)

402After Incident
CRITICAL-93
PEN3232532110625
The University of Pennsylvania suffered a targeted email hack where attackers exploited a PennKey single sign-on (SSO) account belonging to a university employee via social engineering. The breach granted unauthorized access to multiple systems, including the Customer Relationship Management (CRM) platform, file repositories, a reporting application, and Marketing Cloud, compromising data of 1.2 million students, alumni, and donors. Hackers claimed to have stolen donor records, bank transactions, and internal memos, threatening to sell or leak the data for financial gain. While Penn restored systems and engaged law enforcement (FBI) and CrowdStrike for investigation, the full scope of exposed data remains unverified. The attack involved mass phishing emails sent from the Graduate School of Education’s system, demanding ransom and criticizing the university’s security. Victims are now filing lawsuits, alleging negligence in safeguarding personal information. The university has yet to confirm the exact data stolen but advises affected individuals to enable credit freezes, multi-factor authentication (MFA), and password resets as precautionary measures.
INCIDENT DETAILS -
TYPE
Data BreachEmail HackCredential TheftSocial Engineering
MOTIVATION
Financial GainData Theft for ResaleExtortion (threatened leak of 'all your data')
IMPACT
Donor RecordsBank TransactionsInternal MemosStudent/Alumni/Donor PII (claimed 1.2M records)Marketing Cloud DataFile Repository ContentsPennKey SSOCustomer Relationship Management (CRM)File RepositoriesReporting ApplicationMarketing CloudGraduate School of Education Email SystemDowntime: Systems restored within ~1 week (by 2025-11-08)Mass Fraudulent Emails SentOngoing Investigation DisruptionsReputation DamageLegal Liabilities (Multiple Lawsuits Filed)Multiple Lawsuits from AlumniCommunity Outrage Over Security FailuresSevere; Public Criticism of 'Dogshit Elitist Institution'Loss of Trust in Data SecurityNegative Media CoverageFour Lawsuits Filed (as of 2025-11-05)Allegations of Negligence in Data SecurityPotential Regulatory ScrutinyHigh; Experts Recommend Credit FreezesPII of 1.2M+ Individuals Potentially ExposedBank Transaction Data AccessedDonor Financial Records Compromised
DATA BREACH
Personally Identifiable Information (PII)Donor Financial RecordsInternal University DocumentsBank TransactionsMarketing DataNumber Of Records Exposed: 1,200,000 (claimed; unverified by Penn)Sensitivity Of Data: High (financial, PII, internal communications)Data Exfiltration: Yes (documents leaked on LeakForum; data threatened for sale)PDFs (Internal Memos)Spreadsheets (Donor/Bank Data)EmailsCRM ExportsNamesEmail AddressesDonor ProfilesPotential SSNs/Financial Data (unconfirmed)
OCTOBER 2025
582Before Incident
Breach
01 Oct 2025PAS
University of Pennsylvania (UPenn)

University of Pennsylvania Data Breach (2025)

489After Incident
CRITICAL-93
PEN4092440110525
In late October 2025, the University of Pennsylvania suffered a major data breach after a hacker compromised an employee’s PennKey SSO account, gaining unauthorized access to critical systems, including the VPN, Salesforce, analytics platforms, and internal files. The attacker exfiltrated sensitive personally identifiable information (PII) of approximately 1.2 million students, alumni, and donors, including names, dates of birth, addresses, phone numbers, financial/demographic data (estimated net worth, donation history), race, religion, and sexual orientation. The breach escalated when the hacker sent offensive emails to hundreds of thousands of recipients via Penn’s mailing list and publicly leaked samples of stolen data as proof. The incident was reported to the FBI, and the university issued a cybersecurity notice on November 4, 2025. Victims face risks of identity theft, phishing, and financial fraud, with legal firms (e.g., Shamis & Gentile P.A.) investigating potential class-action lawsuits for compensation covering credit monitoring, identity protection, and financial losses.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessIdentity Theft Risk
MOTIVATION
Data TheftFinancial Gain (potential ransom or dark web sale)Disruption (offensive emails)
IMPACT
NamesDates of BirthAddressesPhone NumbersFinancial/Demographic Information (net worth, donation history)RaceReligionSexual OrientationVPNSalesforceAnalytics PlatformsInternal FilesMailing List PlatformUnauthorized Email CampaignsReputation DamageInvestigation/Remediation CostsLikely (given offensive emails and PII exposure)High (Ivy League institution; sensitive data exposed)Potential Lawsuits (class action by Shamis & Gentile P.A.)Regulatory ScrutinyHigh (PII exposed)
DATA BREACH
PIIFinancial DataDemographic DataSensitive Personal Attributes (race, religion, sexual orientation)Number Of Records Exposed: 1,200,000Sensitivity Of Data: HighDatabasesInternal DocumentsMailing Lists
MAY 2025
627Before Incident
Breach
01 May 2025PAS
University of Pennsylvania (UPenn)

University of Pennsylvania Cyberattack and Data Breach

565After Incident
CRITICAL-62
PEN0862408110725
The University of Pennsylvania (UPenn) suffered a cyberattack involving sophisticated identity impersonation (social engineering), allowing attackers to gain unauthorized access to internal systems linked to fundraising and alumni databases. The breach was detected after a fraudulent email was sent from Penn’s Graduate School of Education, triggering an investigation that uncovered the intrusion.Former students have filed lawsuits, alleging UPenn failed to adequately protect their personal, academic, and financial records, which may have been exposed. While the university contained the breach and restored affected systems, the long-term risks remain unclear, including potential misuse of stolen data (e.g., identity theft, fraud). The FBI is investigating, and UPenn has enlisted CrowdStrike for forensic analysis and defense reinforcement.The incident has damaged UPenn’s reputation, with alumni demanding transparency on what data was compromised, notification timelines, and preventive measures. The breach highlights broader concerns about how long universities must safeguard alumni data and the risks of storing decades-old records on interconnected systems. Legal outcomes may influence cybersecurity standards for higher education institutions nationwide.
INCIDENT DETAILS -
TYPE
data breachunauthorized accesssocial engineering
IMPACT
personal dataacademic historiesfinancial recordsalumni/fundraising database recordsemail system (Graduate School of Education)fundraising systemsalumni databasesOperational Impact: temporary disruption; systems later restoredlawsuits from former studentsdemands for transparencyreputational damageloss of trust among alumnilegal scrutinymultiple lawsuits from former studentspotential regulatory scrutinyIdentity Theft Risk: high (long-term risk for alumni)
DATA BREACH
personal dataacademic recordsfinancial recordsalumni/fundraising dataSensitivity Of Data: high (includes PII, academic, and financial records)
NOVEMBER 2024
705Before Incident
Breach
02 Nov 2024PAS
University of Pennsylvania (Penn)

University of Pennsylvania Data Breach and Class Action Lawsuits

612After Incident
CRITICAL-93
PEN1962019110525
The University of Pennsylvania (Penn) suffered a significant data breach targeting its information systems, compromising the confidential data of 1.2 million students, alumni, and donors. The breach, disclosed on November 2, 2024, led to a wave of class-action lawsuits from graduates alleging negligence in cybersecurity measures. Plaintiffs claim Penn failed to maintain adequate security systems, monitor for intrusions, or ensure third-party vendors followed proper protocols. The stolen data reportedly includes Personally Identifiable Information (PII), though the full scope remains under investigation. Penn confirmed the breach was contained but has not detailed the exact nature of the exposed data. Lawsuits argue the impact is far broader than acknowledged, with long-term repercussions expected for affected individuals, including potential identity theft, financial fraud, or reputational harm. The incident underscores systemic vulnerabilities in Penn’s data protection framework, raising concerns over compliance and trust among stakeholders.
INCIDENT DETAILS -
TYPE
Data BreachClass Action Lawsuits
IMPACT
Personally Identifiable Information (PII) of students, alumni, and donorsSelect information systemsFour class action lawsuits filed by alumniBrand Reputation Impact: Significant (multiple lawsuits alleging negligence)Four class action lawsuits filed (Christopher Kelly, Mary Sikora, Christian Bersani, Kelli Mackey)Identity Theft Risk: Potential (PII exposed)
DATA BREACH
Personally Identifiable Information (PII)Number Of Records Exposed: 1.2 millionSensitivity Of Data: High (PII of students, alumni, and donors)Data Exfiltration: Yes (claimed by hacker)Personally Identifiable Information: Yes
OCTOBER 2023
769Before Incident
Breach
01 Oct 2023PAS
University of Pennsylvania (UPenn)

University of Pennsylvania Data Breach and Class-Action Lawsuit

691After Incident
CRITICAL-78
PEN3394633110425
The University of Pennsylvania (UPenn) suffered a significant cybersecurity breach in late October 2023, where hackers infiltrated inadequately secured email systems and exfiltrated personally identifiable information (PII) of students, alumni, donors, and employees. The breach exposed internal documents, including bank transaction receipts, donor memos, and sensitive PII, which were later dumped publicly. A class-action lawsuit filed by a Penn alumnus alleges negligence, citing UPenn’s failure to implement robust security measures, monitor systems, or enforce vendor safeguards. The attackers, motivated by targeting ultra-high-net-worth individuals, exploited weak authentication protocols. The University reported the incident to the FBI and acknowledged the leak’s severity, though the full scope of misuse (e.g., identity theft, financial fraud) remains unresolved. The lawsuit argues UPenn violated the Federal Trade Commission Act by failing to protect data, with plaintiffs claiming lifelong risks from the exposed information.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessPhishing/SpamClass-Action Lawsuit
MOTIVATION
Financial Gain (Targeting Ultra-High-Net-Worth Individuals)Exploitation of Weak Security for Data Theft
IMPACT
Personally Identifiable Information (PII)Internal University Talking PointsDonor Memos and Family InformationBank Transaction ReceiptsEmail AccountsUniversity Data Systems (Potentially Vendor Systems)Disruption Due to Spam EmailsReputation DamageLegal and Regulatory ScrutinyClass-Action Lawsuit Filed by Alumni and Affected IndividualsSignificant Damage Due to Public Disclosure of Breach and LawsuitLoss of Trust Among Alumni, Donors, and StudentsClass-Action Lawsuit for NegligencePotential Violation of Section 5 of the Federal Trade Commission ActHigh (PII Exposed and Allegedly Targeted for Nefarious Use)Bank Transaction Receipts Compromised
DATA BREACH
Personally Identifiable Information (PII)Internal DocumentsDonor InformationBank Transaction ReceiptsSensitivity Of Data: High (Includes PII, Financial Data, and Confidential University Records)EmailsPDFs (Memos, Talking Points)Bank Transaction RecordsPotentially Other Document TypesNamesEmail AddressesPotentially Other PII (e.g., Financial Details, Donor Information)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for PAS ?
?
What was PAS's A.I Rankiteo Cyber Score in August 2026 ?
?
What was PAS's A.I Rankiteo Cyber Score in July 2026 ?
?
What was PAS's A.I Rankiteo Cyber Score in June 2026 ?
?
What was PAS's A.I Rankiteo Cyber Score in May 2026 ?
?
What was PAS's A.I Rankiteo Cyber Score in April 2026 ?
?
What was PAS's A.I Rankiteo Cyber Score in March 2026 ?
?
What was PAS's A.I Rankiteo Cyber Score in February 2026 ?
?
What was PAS's A.I Rankiteo Cyber Score in January 2026 ?
?
What was PAS's A.I Rankiteo Cyber Score in December 2025 ?
?
What was PAS's A.I Rankiteo Cyber Score in November 2025 ?
?
What was PAS's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on PAS's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with PAS ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view PAS's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Penn Arts & Sciences Cyber Scoring History | Rankiteo