ShinyHunters Alleged Data Breach Targets Ivy League: 2 Million Records Stolen from Harvard University and the University of Pennsylvania

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Record Exposure: The ShinyHunters hacking group claims to have compromised more than 2.2 million records from Harvard University and the University of Pennsylvania.
  • Sensitive Data at Risk: The alleged exfiltration includes personally identifiable information (PII) and sensitive donation-related data from both institutions.
  • Sector Vulnerability: High-value education-sector databases are increasingly targeted by financially motivated cybercriminal groups.

The notorious threat actor group ShinyHunters has claimed responsibility for a significant data breach targeting two of the United States' most prestigious academic institutions: Harvard University and the University of Pennsylvania. On February 4, 2026, the group announced the alleged exfiltration of a massive dataset containing a total of over 2.2 million records. 

While the breach is pending verification, the claims align with the group's historical operational patterns of targeting organizations with vast repositories of user data.

Exposure of PII and Donor Information

According to the threat actors, the compromised databases contain a wealth of sensitive information. The alleged University of Pennsylvania data leak and the Harvard breach reportedly include:

ShinyHunters claims Harvard and the University of Pennsylvania | Source: HackManac on X
ShinyHunters claims Harvard and the University of Pennsylvania | Source: HackManac on X

The ShinyHunters group, known for social engineering techniques, typically monetizes such data by selling it on dark web marketplaces or by using it to extort victim organizations.

Education Sector Cybersecurity Under Siege

If confirmed, this ShinyHunters data breach claim could endanger the impacted individuals. Universities are attractive targets for cybercriminals due to the sheer volume of PII, intellectual property, and financial data they possess. 

In October, Harvard confirmed a Cl0p data breach tied to the Oracle EBS vulnerability, and one month later, UPenn announced investigating an intrusion linked to the same flaw.

In late December, the University of Phoenix data breach of its Oracle EBS system may have compromised the details of nearly 3.5 million individuals.

This week, Mandiant reported that Cloud Environments are targeted with ShinyHunters extortion tactics, vishing, and SSO compromise


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: