University of Phoenix Data Breach via Oracle E-Business Suite Exploit
The University of Phoenix disclosed a significant data breach after attackers exploited a zero-day vulnerability in the Oracle E-Business Suite (EBS) financial application. The breach, detected on November 21, 2025, resulted in unauthorized access to sensitive personal and financial information, including names, contact details, dates of birth, Social Security numbers, and bank account information of numerous current and former students, employees, faculty, and suppliers. The incident was revealed after the university was listed on the leak site of a prominent Russian extortion group, believed to be the Clop ransomware gang, which has targeted multiple U.S. educational institutions through the same Oracle EBS vulnerability.
The university's parent company, Phoenix Education Partners, filed a notice with the U.S. Securities and Exchange Commission (SEC), confirming the breach and stating that cybersecurity insurance would cover the response and remediation costs. While the attackers have not publicly disseminated the stolen data, the university is continuing its investigation and will notify affected individuals and regulatory entities. The breach is part of a broader campaign that has impacted other major universities, highlighting the risks associated with unpatched enterprise software vulnerabilities.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
University of Phoenix publicly discloses breach and begins notifications
On December 3, 2025, University of Phoenix disclosed the data breach, said numerous individuals were impacted, and began notifying affected people and regulators. The university said the stolen data had not yet been publicly disseminated and is offering identity protection services.
University of Pennsylvania confirms related breach and law enforcement cooperation
The University of Pennsylvania confirmed it was also affected by the Oracle EBS breach campaign and said it is cooperating with a federal law enforcement investigation. The university is also offering identity protection services to affected individuals.
University of Phoenix detects breach after November discovery
University of Phoenix said it detected the breach in November 2025, after its data was compromised in the earlier Oracle EBS attack. One report says the university learned of the incident after being listed on Clop's leak site.
University of Phoenix data is accessed in Oracle EBS breach
During the August 2025 Oracle EBS intrusion, attackers accessed University of Phoenix data affecting numerous individuals, including students, staff, faculty, and suppliers. The exposed information included names, contact details, dates of birth, Social Security numbers, and bank account information.
Clop exploits Oracle EBS zero-day in broad data-theft campaign
In August 2025, the Clop extortion group exploited a previously unknown Oracle E-Business Suite vulnerability, identified as CVE-2025-61882, to steal data from multiple organizations. Reported victims in the campaign include major U.S. universities and companies such as Harvard, Dartmouth, the University of Pennsylvania, GlobalLogic, Logitech, The Washington Post, and Envoy Air.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


