Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationeducation-sector-threatmass-credential-exposureransomware-group-operation

University of Phoenix Data Breach Exposes 3.5 Million Records via Oracle EBS Exploit

Updated 3mo agoFirst seen Dec 23, 20253 sources

University of Phoenix suffered a major data breach affecting approximately 3.5 million individuals, including students, staff, and suppliers, after attackers exploited a zero-day vulnerability in the Oracle E-Business Suite (EBS) financial application. The breach, attributed to the Clop ransomware gang, resulted in the exposure of sensitive personal and financial information such as names, contact details, dates of birth, Social Security numbers, and bank account information. The incident was discovered on November 21, 2025, several months after the initial compromise in August, highlighting significant gaps in the university’s security monitoring and detection capabilities.

Following regulatory requirements, especially in Maine where over 9,000 residents were affected, the University of Phoenix issued formal notifications and offered complimentary identity theft protection services, including credit monitoring and fraud reimbursement. The breach has raised concerns about the adequacy of cybersecurity defenses in higher education and prompted the university to engage legal counsel and external experts to manage the response and notification process. The Clop ransomware group’s involvement and the exploitation of a critical Oracle EBS vulnerability underscore the evolving threat landscape facing educational institutions.

Share:
University of Phoenix Data Breach Exposes 3.5 Million Records via Oracle EBS Exploit
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Dec 23, 20256mo ago

Oracle acknowledges EBS zero-days and issues emergency patches

After initially asserting patched systems were safe, Oracle later acknowledged two zero-day vulnerabilities in Oracle E-Business Suite, CVE-2025-61882 and CVE-2025-61884, and released emergency fixes. This disclosure tied the University of Phoenix incident to a wider exploitation campaign.

Clop campaign expands through Oracle EBS zero-day attacks

By late 2025, a broader Clop-linked campaign exploiting Oracle E-Business Suite zero-days had impacted multiple organizations across sectors, including other universities and major enterprises. The activity involved data theft and extortion demands, with researchers and media attributing the operation to the Russian-speaking Clop group.

Dec 22, 20256mo ago

University of Phoenix offers identity protection to affected people

Following disclosure, the university began offering complimentary identity theft or identity protection services to impacted individuals. It also engaged legal and regulatory response processes related to the breach.

University of Phoenix discloses 3.5 million-person data breach

On 2025-12-22, the University of Phoenix publicly disclosed that a breach affected nearly 3.5 million individuals, including students, former attendees, staff, and suppliers. The disclosure included regulatory notifications, including in Maine, and described exposure of sensitive personal information.

Nov 21, 20257mo ago

University of Phoenix discovers the breach

The University of Phoenix detected the compromise on 2025-11-21, months after the initial intrusion. Reports indicate discovery came after the incident was publicly listed by Clop.

Aug 13, 202510mo ago

University of Phoenix breached via Oracle EBS zero-day

Attackers gained unauthorized access to the University of Phoenix environment on 2025-08-13, reportedly exploiting an Oracle E-Business Suite zero-day later identified as CVE-2025-61882. The intrusion led to the theft of sensitive personal and financial data.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

30 LINKEDOpen in app
Threat actors
1 linked
Affected products
6 linked
FtaMoveitE-Business SuiteMoveit TransferCentrestackGoanywhere Managed File Transfer
Organizations
21 linked
University of PhoenixConstangy, Brooks, Smith & Prophete, LLPOracleMoveitGladinetSchneider ElectricLKQ CorporationKnowbe4AccellionEnvoy AirCox CommunicationsCleoResecurityBroadcomVulnCheckAbbott LaboratoriesFortraPhoenix Education PartnersPathAIBitpandaGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

University of Phoenix Data Breach Exposes 3.5 Million Records via Oracle EBS Exploit | Mallory