
- Hackers accessed University systems via stolen SSO credentials, stealing data on 1.2 million individuals
- Offensive mass email followed partial lockout; University later confirmed the breach was real
- Attack exploited weak MFA enforcement among senior staff through social engineering
It seems the “obviously fake” and “fraudulent” claims recently made by the University of Pennsylvania hackers are not so “obviously fake” and “fraudulent”, after all - as the organization has now confirmed hackers stole files from its systems.