CSIDB logo
Incident

Dartmouth College

Incident posture

Attack window
Aug 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:22

Linked entities

Victim
Dartmouth College
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Aug 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware group exploited a zero-day vulnerability in Oracle's E-Business Suite software, resulting in a data breach that exposed nearly 100,000 records at Dartmouth College. The incident was among several higher-education breaches linked to the same third-party software flaw, which collectively accounted for millions of exposed records across the sector. The attack highlighted the growing risk posed by vulnerabilities in third-party systems used by educational institutions.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Dartmouth College was among the higher education institutions affected by a wave of data breaches in 2025 linked to a vulnerability in Oracle's E-Business Suite software. According to Comparitech's education ransomware roundup, the ransomware group CL0P exploited a zero-day flaw in the Oracle software that was unknown to the developers at the time. This third-party software vulnerability allowed the threat actors to compromise data held by multiple institutions, including Dartmouth College. The breach was part of a broader pattern in which a small number of large incidents drove a significant rise in exposed records across the higher education sector during 2025.

The incident at Dartmouth College specifically impacted nearly 100,000 records, as reported by Comparitech's head of data research, Rebecca Moody. These breaches were tied to the August 2025 Oracle E-Business Suite exploit, which ranked among the top three cyber attacks on the higher education sector for that year. The same vulnerability also led to confirmed breaches at other institutions, including the University of Phoenix, which saw 3.5 million records impacted, and the University of Pennsylvania, which had 46,000 records exposed. Comparitech's data on records exposed for that period primarily reflected incidents from the first half of 2025, with additional breach disclosures anticipated to further increase the totals in subsequent months.

The broader trend in 2025 showed that while the overall number of ransomware attacks on educational institutions remained relatively steady compared to 2024, the scale of record exposure grew substantially. Across confirmed attacks in 2025, 3.9 million records were known to have been exposed, marking a 27 percent increase over the 3.1 million records affected in 2024. Higher education institutions bore the brunt of this exposure, with U.S. higher ed attacks breaching 3.7 million records compared to 175,000 for K-12 institutions. Analysts attributed this disparity largely to the third-party Oracle exploit, which highlighted the risks institutions face from vulnerabilities in software supplied by external vendors.

Comparitech's findings underscored how third-party software vulnerabilities amplified the impact on organizations like Dartmouth College that relied on Oracle's E-Business Suite. The fact that the flaw was a zero-day vulnerability meant that institutions had no prior opportunity to patch the software or defend against the exploit before it was actively leveraged by CL0P. This dynamic forced affected institutions, including Dartmouth College, into a reactive posture, dealing with the consequences of data exposure stemming from a supply-chain weakness rather than a direct compromise of their own systems.

Sources

Sources available to members: 1 source.

CSIDB