Data leak
Harvard University and UPenn Data Leaked by ShinyHunters Vishing Campaign
Primary Source βIncident Details
Harvard University and the University of Pennsylvania were named as victims and had data leaked by
ShinyHunters, the prolific hack-and-leak group responsible for numerous high-profile breaches including the
Snowflake UNC5537 campaign. The data was obtained via ShinyHunters’ characteristic vishing social engineering
campaign targeting IT helpdesks at cloud service providers holding Harvard and UPenn data. Exposed data
reportedly included alumni contact information, donor records, or institutional data. Both universities
notified affected individuals. ShinyHunters has previously targeted Santander, Ticketmaster, and dozens of
other organizations through similar cloud provider social engineering campaigns.
Technical Details
- Initial Attack Vector
- ShinyHunters' vishing (voice phishing) social engineering campaign targeting cloud service providers; victims included service providers holding Harvard and UPenn alumni, donor, or student data
Timeline
- 2026-02-04 Breach occurred
- 2026-02-04 Publicly disclosed