← Parexel International

2025 Parexel International — unauthorized access to Oracle-hosted E-Business Suite; employee HR fallout

2025 6.0K records affected Share on X

Data compromised

Names, SSNs, financial account indicators, dates of birth, and payment-card numbers without CVV per consumer-notification summaries

Technical writeup

Clinical research organization Parexel disclosed suspicious activity tied to an Oracle Cloud Infrastructure–hosted Oracle E-Business Suite environment, with consumer-facing summaries and Maine Attorney General mirrors referencing an August–October 2025 access window before December 2025 notification mailings for more than six thousand current and former staff. Comparitech and HIPAA-adjacent blogging stressed payroll and identity-class fields while corporate letters differentiated clinical trial participants as outside the impacted cohort.

Root cause

Criminally abused enterprise application / cloud hosting flaw chain (framed in notices around Oracle EBS exposure)

References