The University of Pennsylvania suffered a data breach after attackers exploited a zero-day vulnerability in Oracle's E-Business Suite (EBS), resulting in the theft of personal information from its systems. The Clop ransomware group is believed to be behind this attack, which targeted numerous Oracle EBS customers worldwide, including other Ivy League institutions such as Dartmouth College and Harvard University. The breach notification filed with Maine's Attorney General confirmed that at least 1,488 individuals were affected, though the total number of victims is likely higher. The university responded by patching its systems after Oracle released fixes and notified federal law enforcement.
The attack was part of a broader campaign in which Clop exploited multiple vulnerabilities in Oracle EBS to steal large amounts of data from various organizations. The University of Pennsylvania only became aware of the breach after Oracle acknowledged the vulnerability and Clop began sending extortion emails to victim organizations. While the university has not disclosed the specific types of data stolen, it has stated that there is no evidence the information has been publicly disclosed or misused. The incident highlights the risks associated with unpatched enterprise software and the growing trend of ransomware groups exploiting zero-day vulnerabilities for data theft and extortion.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
On December 2, 2025, Penn publicly confirmed that attackers exploited the Oracle EBS vulnerability to steal personal data. The university said it was notifying affected individuals, offering credit monitoring, and had found no evidence of public disclosure or misuse of the stolen data.
Following Oracle's fix, Penn patched the affected systems, notified federal law enforcement, and continued investigating with cybersecurity experts. The university also began reinforcing its security posture in response to the breach.
Oracle released a fix for CVE-2025-61882 after the attacks, enabling affected organizations to remediate the exploited Oracle EBS flaw. Victims including the University of Pennsylvania later applied the patches.
After the intrusions, Clop sent extortion emails to victims and publicly boasted about the Oracle EBS attacks, including leaking sample data from breached organizations. Some victims reportedly only learned of the compromise after these extortion efforts and Oracle's disclosure.
A Maine data breach notification published on December 1, 2025, disclosed that the University of Pennsylvania incident affected nearly 1,500 Maine residents. The filing provided the first public indication of the scale of Penn's breach.
During a three-day period in August 2025, the University of Pennsylvania's Oracle EBS environment was compromised, and documents containing personal information were stolen. The breach ultimately affected at least 1,488 individuals, including nearly 1,500 Maine residents reported in state filings.
In August 2025, attackers attributed to the Clop ransomware group began exploiting Oracle E-Business Suite zero-day CVE-2025-61882 and related flaws in a large-scale data theft and extortion campaign affecting nearly 100 organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcecyberscoop.com
Open sourcemaine.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.