Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationeducation-sector-threatransomware-group-operationmass-credential-exposure

University of Phoenix Data Breach via Oracle E-Business Suite Exploit

Updated 3mo agoFirst seen Dec 3, 20252 sources

The University of Phoenix disclosed a significant data breach after attackers exploited a zero-day vulnerability in the Oracle E-Business Suite (EBS) financial application. The breach, detected on November 21, 2025, resulted in unauthorized access to sensitive personal and financial information, including names, contact details, dates of birth, Social Security numbers, and bank account information of numerous current and former students, employees, faculty, and suppliers. The incident was revealed after the university was listed on the leak site of a prominent Russian extortion group, believed to be the Clop ransomware gang, which has targeted multiple U.S. educational institutions through the same Oracle EBS vulnerability.

The university's parent company, Phoenix Education Partners, filed a notice with the U.S. Securities and Exchange Commission (SEC), confirming the breach and stating that cybersecurity insurance would cover the response and remediation costs. While the attackers have not publicly disseminated the stolen data, the university is continuing its investigation and will notify affected individuals and regulatory entities. The breach is part of a broader campaign that has impacted other major universities, highlighting the risks associated with unpatched enterprise software vulnerabilities.

Share:
University of Phoenix Data Breach via Oracle E-Business Suite Exploit
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 3, 20257mo ago

University of Phoenix publicly discloses breach and begins notifications

On December 3, 2025, University of Phoenix disclosed the data breach, said numerous individuals were impacted, and began notifying affected people and regulators. The university said the stolen data had not yet been publicly disseminated and is offering identity protection services.

University of Pennsylvania confirms related breach and law enforcement cooperation

The University of Pennsylvania confirmed it was also affected by the Oracle EBS breach campaign and said it is cooperating with a federal law enforcement investigation. The university is also offering identity protection services to affected individuals.

Nov 1, 20258mo ago

University of Phoenix detects breach after November discovery

University of Phoenix said it detected the breach in November 2025, after its data was compromised in the earlier Oracle EBS attack. One report says the university learned of the incident after being listed on Clop's leak site.

Aug 1, 202511mo ago

University of Phoenix data is accessed in Oracle EBS breach

During the August 2025 Oracle EBS intrusion, attackers accessed University of Phoenix data affecting numerous individuals, including students, staff, faculty, and suppliers. The exposed information included names, contact details, dates of birth, Social Security numbers, and bank account information.

Clop exploits Oracle EBS zero-day in broad data-theft campaign

In August 2025, the Clop extortion group exploited a previously unknown Oracle E-Business Suite vulnerability, identified as CVE-2025-61882, to steal data from multiple organizations. Reported victims in the campaign include major U.S. universities and companies such as Harvard, Dartmouth, the University of Pennsylvania, GlobalLogic, Logitech, The Washington Post, and Envoy Air.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

23 LINKEDOpen in app
Threat actors
1 linked
Organizations
21 linked
Harvard UniversityOracleUniversity of PhoenixUniversity of PennsylvaniaLogitechDartmouth CollegeMoveitfbiCl0pClop extortion groupGlobalLogicU.S. Department of JusticeAccellionEnvoy AirCleoPrinceton UniversityThe Washington PostFortrasecPhoenix Education PartnersDeep Instinct
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.