RANSOMWARE VICTIMEDUCATIONDUPLICATE CLAIM

University of Pennsylvania

shinyhunters📍 United States (US)📅 February 4, 2026
1
linked CVEs
8
same group

Attack Intelligence

University of Pennsylvania was compromised in a ransomware attack attributed to shinyhunters in February 2026. The organization, operating in the Education sector in United States, was added to the group's data leak site as part of an extortion campaign.

shinyhunters operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Records: 1.2M Records | Updated: 04 Feb 2026 | Note: Make the right decision, don't be the next headline. | This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you.

Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2026-35273, which may have been leveraged as initial access vectors or for lateral movement.

Additional Details

Correlated Vulnerabilities (1)

Other Victims — shinyhunters (8)

Quick Facts

CountryUnited States (US)
SectorEducation
Attack DateFeb 4, 2026
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

shinyhunters
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.