← University of Phoenix

2025 University of Phoenix — Oracle EBS Clop zero-day; students, staff, suppliers

2025 Unknown records affected Share on X

Data compromised

Names, contact info, DOB, SSNs, bank account and routing numbers for students, employees, faculty, and suppliers

Technical writeup

University of Phoenix disclosed in December 2025 that attackers exploited a zero-day in Oracle E-Business Suite financial software to steal sensitive personal and financial data belonging to current and former students, employees, faculty, and suppliers. Phoenix Education Partners filed an SEC 8-K; the school detected the incident November 21 after Clop added UoPX to its leak site. Disclosed categories include names, contact information, dates of birth, Social Security numbers, and bank account/routing numbers. The university had not published a consolidated victim count at initial trade-press reporting.

Root cause

Clop exploitation of Oracle E-Business Suite zero-day CVE-2025-61882

References