Phone phishers targeted a Princeton University employee with ordinary database access on 10 November 2025, compromising biographical information about alumni, donors, students and community members. Princeton’s incident response team discovered and ejected the attackers within 24 hours.
On 18 November, Harvard University discovered unauthorised access to its Alumni Affairs and Development systems following a phone-based phishing attack, exposing contact details, addresses, event attendance records, donation details and biographical information.
Three Institutions, One Sector, Five Weeks
With Penn at 25-1028, this is the sector-rotation pattern the corpus filed at 25-0512 and traced across 2025 at 25-0702 — retail, then insurance, then aviation, then a platform.
Higher education development offices are the same shape of target: a support function with broad database access, a large intermediary population of staff and volunteers, and a service culture built on being helpful to people it cannot identify by sight.
Princeton Ejected Them Within A Day
That is the detail worth extracting. This corpus records dwell times of 102 days at Nevada, five months at 25-0820 and ten months at 26-0620. Twenty-four hours is an outlier by two orders of magnitude.
It also demonstrates what the corpus argued at 25-1125: prevention will fail, and detection determines whether a failed prevention becomes a catastrophe. Princeton was compromised. The difference was what happened next.
This desk filed at 25-0807 that a database assembled from disclosures records failures in detail and successes almost never. This is one of the few detection successes in the corpus with a time attached.
An Employee With Ordinary Access Was Enough
The Princeton account specifies ordinary database access, not administrative privilege. That is consistent with the campaign pattern throughout: the objective is not domain administration but a session that can read the records.
It is the argument at 25-0701 — the blast radius of a successful call is set by how much a single ordinary session can reach, which is an architectural decision made long before, by people not thinking about telephones.
Compiled from public reporting and university statements, listed below. No actor is named. We do not assert that the three university incidents share a common actor. Corrections: corrections@forensicpost.com.
- Harvard University discloses data breach affecting alumni, donorsBleepingComputer
- Princeton database breached in targeted phishing incidentPrinceton Alumni Weekly
- Data breach at Harvard’s development office may have exposed donor recordsThe Harvard Crimson