University of Phoenix
Incident posture
Linked entities
- Victim
- University of Phoenix
- Threat actors
- 3 actors
- Sources
- 3 sources
Timeline
Summary
The University of Phoenix disclosed a major data breach affecting 3,489,274 individuals, including current and former students, faculty, staff, and suppliers, after attackers exploited a zero-day vulnerability tracked as CVE-2025-61882 in Oracle's E-Business Suite during a multi-day window in August. The intrusion went undetected until late November, when the Clop ransomware group listed the institution on a public leak site following the theft of highly sensitive personal and financial information such as full names, contact details, dates of birth, Social Security numbers, and bank account and routing data. The incident is part of a broader Clop campaign leveraging the same Oracle flaw against other universities including Harvard, the University of Pennsylvania, and Dartmouth College. The institution has engaged third-party forensic experts, is cooperating with law enforcement, and is offering affected individuals twelve months of complimentary credit monitoring, identity theft recovery assistance, dark web surveillance, and a fraud reimbursement policy.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The University of Phoenix confirmed a major data breach affecting 3,489,274 individuals, making it one of the largest higher-education cyber incidents of 2025. The breach was linked to a zero-day vulnerability in Oracle's E-Business Suite, tracked as CVE-2025-61882. Security researchers attributed the exploitation to the Clop ransomware group, a threat actor described in reporting as Russian-linked and known for conducting data-extortion campaigns rather than traditional ransomware encryption. According to notification letters filed with the Maine Attorney General's Office, attackers accessed the university's network between August 13 and August 22, 2025. The university did not detect the unauthorized activity until November 21, 2025, a gap of roughly three months during which sensitive data remained exposed within the compromised environment.
The intrusion came to light after the attackers listed the University of Phoenix on a public leak site. Following this listing, the university disclosed the incident in early December 2025, and its parent company filed an 8-K with regulators. The university's Oracle E-Business Suite environment handled financial operations and contained highly sensitive personal and financial information. Compromised data included full names, contact information, dates of birth, Social Security numbers, bank account numbers, and routing numbers. The affected population comprised current and former students, faculty, staff, and suppliers of the for-profit institution. Notification letters were sent to affected individuals, including 9,131 Maine residents, with delivery occurring by postal mail rather than email.
The breach formed part of a broader Clop campaign exploiting the same Oracle E-Business Suite vulnerability, which Comparitech researchers described as affecting more than 100 organizations across multiple sectors. Higher-education institutions were disproportionately impacted in terms of record exposure, and the Oracle exploit accounted for the three largest higher-ed breaches recorded in 2025. Beyond the University of Phoenix, the campaign affected Harvard University, the University of Pennsylvania, and Dartmouth College. Reporting indicated that the University of Pennsylvania incident involved approximately 46,000 records, while Dartmouth College's breach involved nearly 100,000 records. Comparitech's head of data research, Rebecca Moody, noted that the University of Phoenix breach ranked as the fourth-largest ransomware attack globally in 2025 based on records affected. Collectively, the Oracle-linked incidents contributed to a sharp rise in exposed education-sector records, with higher education alone seeing 3.7 million records breached in 2025 compared to 1.9 million in 2024.
The scale of the University of Phoenix incident reflected the volume of personal and financial data historically accumulated by the institution. As a for-profit university with a large alumni and current-student base, the organization retained years of records tied to millions of individuals. The breach exposed data sufficient to enable identity theft, financial fraud, and targeted phishing campaigns. Despite the magnitude of the data theft, no University of Phoenix information appeared publicly on dark web forums following the listing, although attackers had released files from other victims in the same campaign.
In response to the breach, the University of Phoenix engaged third-party forensics experts and cooperated with law enforcement. The institution offered affected individuals 12 months of complimentary identity protection services, including credit monitoring, identity-theft recovery assistance, dark-web surveillance, and a $1 million fraud-reimbursement policy. Enrollment in these services required the use of a redemption code provided in the official notification letters. The university's incident response aligned with regulatory disclosure obligations through filings with the Maine Attorney General's Office and the 8-K submission by its parent company. The combination of delayed detection, the breadth of exposed data types, and the institution's large affected population made the University of Phoenix breach a defining case in the 2025 education-sector threat landscape.
Sources
Sources available to members: 3 sources.