University of Phoenix suffered a major data breach affecting approximately 3.5 million individuals, including students, staff, and suppliers, after attackers exploited a zero-day vulnerability in the Oracle E-Business Suite (EBS) financial application. The breach, attributed to the Clop ransomware gang, resulted in the exposure of sensitive personal and financial information such as names, contact details, dates of birth, Social Security numbers, and bank account information. The incident was discovered on November 21, 2025, several months after the initial compromise in August, highlighting significant gaps in the university’s security monitoring and detection capabilities.
Following regulatory requirements, especially in Maine where over 9,000 residents were affected, the University of Phoenix issued formal notifications and offered complimentary identity theft protection services, including credit monitoring and fraud reimbursement. The breach has raised concerns about the adequacy of cybersecurity defenses in higher education and prompted the university to engage legal counsel and external experts to manage the response and notification process. The Clop ransomware group’s involvement and the exploitation of a critical Oracle EBS vulnerability underscore the evolving threat landscape facing educational institutions.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
After initially asserting patched systems were safe, Oracle later acknowledged two zero-day vulnerabilities in Oracle E-Business Suite, CVE-2025-61882 and CVE-2025-61884, and released emergency fixes. This disclosure tied the University of Phoenix incident to a wider exploitation campaign.
By late 2025, a broader Clop-linked campaign exploiting Oracle E-Business Suite zero-days had impacted multiple organizations across sectors, including other universities and major enterprises. The activity involved data theft and extortion demands, with researchers and media attributing the operation to the Russian-speaking Clop group.
Following disclosure, the university began offering complimentary identity theft or identity protection services to impacted individuals. It also engaged legal and regulatory response processes related to the breach.
On 2025-12-22, the University of Phoenix publicly disclosed that a breach affected nearly 3.5 million individuals, including students, former attendees, staff, and suppliers. The disclosure included regulatory notifications, including in Maine, and described exposure of sensitive personal information.
The University of Phoenix detected the compromise on 2025-11-21, months after the initial intrusion. Reports indicate discovery came after the incident was publicly listed by Clop.
Attackers gained unauthorized access to the University of Phoenix environment on 2025-08-13, reportedly exploiting an Oracle E-Business Suite zero-day later identified as CVE-2025-61882. The intrusion led to the theft of sensitive personal and financial data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcebankinfosecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.