University of Pennsylvania investigating offensive email sent through graduate school system

The University of Pennsylvania is investigating an email that was sent out to thousands of current and former students on Friday afternoon containing offensive language and threats of a data breach. 

A spokesperson for the university told Recorded Future News that the email, sent from an address belonging to the Graduate School of Education (GSE), is fraudulent.

“This is obviously a fake, and nothing in the highly offensive, hurtful message reflects the mission or actions of Penn or of Penn GSE,” the spokesperson said. “The University’s Office of Information Security is aware of the situation, and our Incident Response team is actively addressing it.” 

The spokesperson did not respond to further questions about whether there has been a breach of the university’s systems. 

A banner on the university website makes a similar statement and adds that recipients should “disregard or delete the message.”

“However, if you receive any new or different messages that raise concern, please contact your local IT support provider (LSP),” the message said. 

The email leveled a range of criticisms at the school and threatened to leak data purportedly stolen from the university. 

It claimed the university “loves… unqualified affirmative action admits” and accused the school of flouting federal rules governing student records as well as the Supreme Court’s 2023 ruling around race-based admissions. 

The email bears the hallmarks of recent cyberattacks on Columbia University, New York University and the University of Minnesota that occurred in the wake of the Supreme Court decision to strike down affirmative action

In the University of Minnesota and New York University breaches, the hacker explicitly came forward to say their goal was to prove that schools are not abiding by the Supreme Court ruling because they have continued to admit Black and Latino students.

After the Columbia University incident — which exposed the sensitive personal information of more than 860,000 people — the hacker provided tranches of the data to conservative activists who have railed against affirmative action, as well as to Bloomberg News and The New York Times, both of which ran controversial stories based on the stolen information.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

 

Total
0
Shares
Previous Post

Chinese hackers scanning, exploiting Cisco ASA firewalls used by governments worldwide

Next Post

ASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability

Related Posts

FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks

The U.S. Federal Bureau of Investigation (FBI) has issued a flash alert to release indicators of compromise (IoCs) associated with two cybercriminal groups tracked as UNC6040 and UNC6395 for orchestrating a string of data theft and extortion attacks. "Both groups have recently been observed targeting organizations' Salesforce platforms via different initial access mechanisms," the FBI said.
Read More

FreePBX Servers Targeted by Zero-Day Flaw, Emergency Patch Now Available

The Sangoma FreePBX Security Team has issued an advisory warning about an actively exploited FreePBX zero-day vulnerability that impacts systems with an administrator control panel (ACP) exposed to the public internet. FreePBX is an open-source private branch exchange (PBX) platform widely used by businesses, call centers, and service providers to manage voice communications. It's built on top
Read More

Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery

Eclipse Foundation, which maintains the open-source Open VSX project, said it has taken steps to revoke a small number of tokens that were leaked within Visual Studio Code (VS Code) extensions published in the marketplace. The action comes following a report from cloud security company Wiz earlier this month, which found several extensions from both Microsoft's VS Code Marketplace and Open VSX
Read More