February 17, 2026
Ransomware targeting universities remains persistent
Denison Security
Public security reports have been released confirming the impact of an October 2025 ransomware attack on Harvard University and the University of Pennsylvania (UPenn). Both attacks have been attributed to the same threat actor, publicly tracked as ShinyHunters.
The extortion group released datasets allegedly containing over 1 million records from Harvard University and 1.2 million records from UPenn, claiming they include personal and donor data. Personally identifiable information (PII) and intimate institutional strategies may have been exposed as a part of this breach.
Experts familiar with the case believe that the threat actors were able to access UPenn’s systems by phishing over voice, known as vishing. Victims were convinced to give up credentials to important business systems by the threat actors.
Conventional wisdom remains true to stop phishing, smishing (phishing over SMS), and vishing (phishing over voice):
- Be cautious with unexpected calls, text messages, or emails requesting sensitive information or asking you to reset your password, even if they appear to come from colleagues or trusted partners.
- Don’t respond to messages, click any links, or download any attachments from suspicious messages.
- Don’t follow any instructions provided until you verify the message is legitimate.
- Verify a message’s authenticity using a trusted communication method.
- Report suspicious emails to isitsafe@denison.edu.
- Contact the Service Desk with questions or concerns.