University of Pennsylvania Data Breach Notice (Oregon Attorney General)
If you received a notice from University of Pennsylvania, here’s what the filing says was exposed, and what to do about it.
University of Pennsylvania notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on December 22, 2025. The filing puts the incident itself on November 11, 2025.
The University of Pennsylvania has notified 2,722 Oregon residents that their personal information was exposed in an incident that occurred on November 11, 2025. The filing with the Oregon Department of Justice was made on December 22, 2025 — 41 days later.
No passwords or credentials were involved
This is important. The record lists only personal information. There is no indication that any password, login detail, or credential was exposed. You do not need to change any University of Pennsylvania password because of this incident. That particular risk does not apply here.
What the exposed personal information actually means for you
Names combined with addresses and other identifying details do not expire. Once they leave an organisation’s control they can be used years from now to support identity theft, fraudulent loan applications, tax fraud, or impersonation attempts. The fact that the university waited just over a month before notifying affected individuals does not change the permanent nature of this exposure.
The filing does not disclose the exact root cause, whether the data was copied and taken, or any further technical details. It simply establishes that personal information belonging to 2,722 people was involved in the November 11 incident.
How to tell whether this filing includes you
The University of Pennsylvania is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not part of this group. However, if you have moved since November 11, 2025, a letter may have gone to an old address. In that case you should contact the university directly to confirm whether you were affected.
The long-term risk that cannot be patched
Unlike a credit card number that can be cancelled or a password that can be changed, the core personal information listed in this filing cannot be reissued. Once it is out, it stays out. This is the central fact that shapes every protective step you take from now on. Criminals do not need to use the data immediately. They can hold it for months or years until an opportunity appears.
What you can still control
You cannot make the exposed data disappear, but you can limit what criminals are able to do with it. The most effective defences focus on early detection and on reducing the number of places where your identity can be used without additional verification.
- Place a freeze on your credit files at Equifax, Experian, and TransUnion. This stops new accounts from being opened in your name without your explicit permission. It is the single most useful step for this type of exposure.
- Review your tax filings carefully in the coming years. Identity thieves sometimes file false returns to claim refunds. Set up IRS online account access now so you receive alerts before any fraudulent filing appears.
- Monitor bank, credit card, and medical insurance statements for unfamiliar activity. Because the exposed data includes personal identifiers, scammers may attempt to redirect legitimate payments or open fraudulent medical billing accounts.
- Be extremely cautious with any unsolicited contact that asks you to confirm personal details or claims to be from the University of Pennsylvania, a government agency, or a bank. Use published phone numbers rather than any number provided in the contact.
Why the 41-day gap matters
The incident date and the filing date are both public. The 41 days between November 11 and December 22, 2025, is the only timing information available. The record contains no discovery date, so it is not possible to know how long the university was aware of the problem before notifying people. What matters to you is that the data has now been acknowledged as exposed and the clock on potential misuse has started.
This filing is limited to personal information. No passwords were exposed, no financial account numbers are listed in the categories, and no permanent government identifiers such as Social Security numbers are confirmed in the public record. That narrows the immediate risks but does not eliminate the long-term identity theft potential created by the loss of personal details.
The University of Pennsylvania has an obligation to send direct notice to everyone whose information was included. For the 2,722 Oregon residents named in this filing, that letter is the clearest confirmation of whether you are affected. Treat its absence as meaningful, while recognising that address changes since the November incident can prevent delivery.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Harvard University Alumni & Donor Data Breach — November 2025
ShinyHunters (Scattered Lapsus$ Hunters) dumped ~115,000 sensitive records from Harvard's Alumni Aff…
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…