PAS A.I CyberSecurity Scoring
PAS
Company Information
Website:https://www.sas.upenn.edu
Employees number:56
Number of followers:3,296
NAICS:6113
Industry Type:Higher Education
Homepage:upenn.edu
PAS Risk Score (AI oriented)
Between 0 and 549
PASHigher Education
Updated:
01/04/2026
01/04/2026
433/1000
Critical
C
PAS Global Score (TPRM)
xxxx
PASHigher Education
Score locked

PASCritical
Current Score
433C (CRITICAL)
01000
5 incidents
-93 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
465
AUGUST 2026
459
JULY 2026
457
JUNE 2026
451
MAY 2026
440
APRIL 2026
435
MARCH 2026
433
FEBRUARY 2026
427
JANUARY 2026
421
DECEMBER 2025
410
NOVEMBER 2025
495
Breach
06 Nov 2025 • PAS
University of Pennsylvania (Penn)
University of Pennsylvania Email Hack and Data Breach (2025)
402
CRITICAL-93
PEN3232532110625
The University of Pennsylvania suffered a targeted email hack where attackers exploited a PennKey single sign-on (SSO) account belonging to a university employee via social engineering. The breach granted unauthorized access to multiple systems, including the Customer Relationship Management (CRM) platform, file repositories, a reporting application, and Marketing Cloud, compromising data of 1.2 million students, alumni, and donors. Hackers claimed to have stolen donor records, bank transactions, and internal memos, threatening to sell or leak the data for financial gain. While Penn restored systems and engaged law enforcement (FBI) and CrowdStrike for investigation, the full scope of exposed data remains unverified. The attack involved mass phishing emails sent from the Graduate School of Education’s system, demanding ransom and criticizing the university’s security. Victims are now filing lawsuits, alleging negligence in safeguarding personal information. The university has yet to confirm the exact data stolen but advises affected individuals to enable credit freezes, multi-factor authentication (MFA), and password resets as precautionary measures.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
582
Breach
01 Oct 2025 • PAS
University of Pennsylvania (UPenn)
University of Pennsylvania Data Breach (2025)
489
CRITICAL-93
PEN4092440110525
In late October 2025, the University of Pennsylvania suffered a major data breach after a hacker compromised an employee’s PennKey SSO account, gaining unauthorized access to critical systems, including the VPN, Salesforce, analytics platforms, and internal files. The attacker exfiltrated sensitive personally identifiable information (PII) of approximately 1.2 million students, alumni, and donors, including names, dates of birth, addresses, phone numbers, financial/demographic data (estimated net worth, donation history), race, religion, and sexual orientation. The breach escalated when the hacker sent offensive emails to hundreds of thousands of recipients via Penn’s mailing list and publicly leaked samples of stolen data as proof. The incident was reported to the FBI, and the university issued a cybersecurity notice on November 4, 2025. Victims face risks of identity theft, phishing, and financial fraud, with legal firms (e.g., Shamis & Gentile P.A.) investigating potential class-action lawsuits for compensation covering credit monitoring, identity protection, and financial losses.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2025
627
Breach
01 May 2025 • PAS
University of Pennsylvania (UPenn)
University of Pennsylvania Cyberattack and Data Breach
565
CRITICAL-62
PEN0862408110725
The University of Pennsylvania (UPenn) suffered a cyberattack involving sophisticated identity impersonation (social engineering), allowing attackers to gain unauthorized access to internal systems linked to fundraising and alumni databases. The breach was detected after a fraudulent email was sent from Penn’s Graduate School of Education, triggering an investigation that uncovered the intrusion.Former students have filed lawsuits, alleging UPenn failed to adequately protect their personal, academic, and financial records, which may have been exposed. While the university contained the breach and restored affected systems, the long-term risks remain unclear, including potential misuse of stolen data (e.g., identity theft, fraud). The FBI is investigating, and UPenn has enlisted CrowdStrike for forensic analysis and defense reinforcement.The incident has damaged UPenn’s reputation, with alumni demanding transparency on what data was compromised, notification timelines, and preventive measures. The breach highlights broader concerns about how long universities must safeguard alumni data and the risks of storing decades-old records on interconnected systems. Legal outcomes may influence cybersecurity standards for higher education institutions nationwide.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2024
705
Breach
02 Nov 2024 • PAS
University of Pennsylvania (Penn)
University of Pennsylvania Data Breach and Class Action Lawsuits
612
CRITICAL-93
PEN1962019110525
The University of Pennsylvania (Penn) suffered a significant data breach targeting its information systems, compromising the confidential data of 1.2 million students, alumni, and donors. The breach, disclosed on November 2, 2024, led to a wave of class-action lawsuits from graduates alleging negligence in cybersecurity measures. Plaintiffs claim Penn failed to maintain adequate security systems, monitor for intrusions, or ensure third-party vendors followed proper protocols. The stolen data reportedly includes Personally Identifiable Information (PII), though the full scope remains under investigation. Penn confirmed the breach was contained but has not detailed the exact nature of the exposed data. Lawsuits argue the impact is far broader than acknowledged, with long-term repercussions expected for affected individuals, including potential identity theft, financial fraud, or reputational harm. The incident underscores systemic vulnerabilities in Penn’s data protection framework, raising concerns over compliance and trust among stakeholders.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2023
769
Breach
01 Oct 2023 • PAS
University of Pennsylvania (UPenn)
University of Pennsylvania Data Breach and Class-Action Lawsuit
691
CRITICAL-78
PEN3394633110425
The University of Pennsylvania (UPenn) suffered a significant cybersecurity breach in late October 2023, where hackers infiltrated inadequately secured email systems and exfiltrated personally identifiable information (PII) of students, alumni, donors, and employees. The breach exposed internal documents, including bank transaction receipts, donor memos, and sensitive PII, which were later dumped publicly. A class-action lawsuit filed by a Penn alumnus alleges negligence, citing UPenn’s failure to implement robust security measures, monitor systems, or enforce vendor safeguards. The attackers, motivated by targeting ultra-high-net-worth individuals, exploited weak authentication protocols. The University reported the incident to the FBI and acknowledged the leak’s severity, though the full scope of misuse (e.g., identity theft, financial fraud) remains unresolved. The lawsuit argues UPenn violated the Federal Trade Commission Act by failing to protect data, with plaintiffs claiming lifelong risks from the exposed information.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for PAS ??
What was PAS's A.I Rankiteo Cyber Score in August 2026 ??
What was PAS's A.I Rankiteo Cyber Score in July 2026 ??
What was PAS's A.I Rankiteo Cyber Score in June 2026 ??
What was PAS's A.I Rankiteo Cyber Score in May 2026 ??
What was PAS's A.I Rankiteo Cyber Score in April 2026 ??
What was PAS's A.I Rankiteo Cyber Score in March 2026 ??
What was PAS's A.I Rankiteo Cyber Score in February 2026 ??
What was PAS's A.I Rankiteo Cyber Score in January 2026 ??
What was PAS's A.I Rankiteo Cyber Score in December 2025 ??
What was PAS's A.I Rankiteo Cyber Score in November 2025 ??
What was PAS's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on PAS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with PAS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view PAS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?