Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationbreach-disclosure-notificationeducation-sector-threatactively-exploited-vulnerability

University of Pennsylvania Data Breach via Clop Exploitation of Oracle E-Business Suite

Updated 3mo agoFirst seen Dec 2, 20256 sources

The University of Pennsylvania suffered a data breach after attackers exploited a zero-day vulnerability in Oracle's E-Business Suite (EBS), resulting in the theft of personal information from its systems. The Clop ransomware group is believed to be behind this attack, which targeted numerous Oracle EBS customers worldwide, including other Ivy League institutions such as Dartmouth College and Harvard University. The breach notification filed with Maine's Attorney General confirmed that at least 1,488 individuals were affected, though the total number of victims is likely higher. The university responded by patching its systems after Oracle released fixes and notified federal law enforcement.

The attack was part of a broader campaign in which Clop exploited multiple vulnerabilities in Oracle EBS to steal large amounts of data from various organizations. The University of Pennsylvania only became aware of the breach after Oracle acknowledged the vulnerability and Clop began sending extortion emails to victim organizations. While the university has not disclosed the specific types of data stolen, it has stated that there is no evidence the information has been publicly disclosed or misused. The incident highlights the risks associated with unpatched enterprise software and the growing trend of ransomware groups exploiting zero-day vulnerabilities for data theft and extortion.

Share:
University of Pennsylvania Data Breach via Clop Exploitation of Oracle E-Business Suite
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Dec 2, 20257mo ago

University of Pennsylvania publicly confirms Oracle EBS data breach

On December 2, 2025, Penn publicly confirmed that attackers exploited the Oracle EBS vulnerability to steal personal data. The university said it was notifying affected individuals, offering credit monitoring, and had found no evidence of public disclosure or misuse of the stolen data.

University of Pennsylvania patches systems and notifies law enforcement

Following Oracle's fix, Penn patched the affected systems, notified federal law enforcement, and continued investigating with cybersecurity experts. The university also began reinforcing its security posture in response to the breach.

Oracle releases patches for the exploited EBS vulnerability

Oracle released a fix for CVE-2025-61882 after the attacks, enabling affected organizations to remediate the exploited Oracle EBS flaw. Victims including the University of Pennsylvania later applied the patches.

Clop publicly extorts Oracle EBS victims and leaks samples

After the intrusions, Clop sent extortion emails to victims and publicly boasted about the Oracle EBS attacks, including leaking sample data from breached organizations. Some victims reportedly only learned of the compromise after these extortion efforts and Oracle's disclosure.

Dec 1, 20257mo ago

Maine breach filing discloses Penn impact on nearly 1,500 residents

A Maine data breach notification published on December 1, 2025, disclosed that the University of Pennsylvania incident affected nearly 1,500 Maine residents. The filing provided the first public indication of the scale of Penn's breach.

Aug 1, 202511mo ago

University of Pennsylvania is breached over three days in August

During a three-day period in August 2025, the University of Pennsylvania's Oracle EBS environment was compromised, and documents containing personal information were stolen. The breach ultimately affected at least 1,488 individuals, including nearly 1,500 Maine residents reported in state filings.

Clop begins exploiting Oracle EBS zero-day in broad campaign

In August 2025, attackers attributed to the Clop ransomware group began exploiting Oracle E-Business Suite zero-day CVE-2025-61882 and related flaws in a large-scale data theft and extortion campaign affecting nearly 100 organizations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Threat actors
1 linked
Organizations
17 linked
OracleUniversity of PennsylvaniaCl0pHarvard UniversityLogitechDartmouth CollegeGlobalLogicEnvoy AirThe Washington PostCox CommunicationsPhoenix Education PartnersUniversity of PhoenixExperianU.S. State DepartmentPrinceton UniversityFederal Law EnforcementMaine Attorney General
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.