2025 University of Phoenix — Oracle EBS Clop zero-day; students, staff, suppliers
Data compromised
Names, contact info, DOB, SSNs, bank account and routing numbers for students, employees, faculty, and suppliers
Technical writeup
University of Phoenix disclosed in December 2025 that attackers exploited a zero-day in Oracle E-Business Suite financial software to steal sensitive personal and financial data belonging to current and former students, employees, faculty, and suppliers. Phoenix Education Partners filed an SEC 8-K; the school detected the incident November 21 after Clop added UoPX to its leak site. Disclosed categories include names, contact information, dates of birth, Social Security numbers, and bank account/routing numbers. The university had not published a consolidated victim count at initial trade-press reporting.
Root cause
Clop exploitation of Oracle E-Business Suite zero-day CVE-2025-61882