More than 35,000 individuals had their sensitive personal information exposed after Dartmouth College experienced a major data breach in which threat actors exploited a zero-day vulnerability in Oracle’s E-Business Suite.

Dartmouth College experienced a major data breach in which threat actors leveraged a zero-day flaw in Oracle’s E-Business Suite, compromising sensitive personal data belonging to over 35,000 people.
Last week, Dartmouth College confirmed a data security incident after attackers exploited a zero-day vulnerability in the college’s Oracle E-Business Suite servers, stealing files containing sensitive personal information.
Oracle E-Business Suite is a popular enterprise resource planning (ERP) system that large organisations use to manage key internal functions such as human resources, finance, and supply chain operations. Clop took advantage of a serious zero-day flaw — mainly CVE-2025-61882 (and possibly others like CVE-2025-61884) — in the Oracle EBS’s BI Publisher component. This bug let them run any code they wanted on the system from a distance without needing to log in.
An investigation into the incident revealed that an “unauthorised actor took certain files between August 9, 2025 and August 12, 2025.” The compromised data included name, Social Security number and financial account information.
The incident was reported to regulators in Maine, California, Texas, and New Hampshire. Dartmouth College stated that more than 35,000 individuals were affected, including over 31,000 in New Hampshire, 1,494 in Maine, and 1,956 in Texas.
The educational institution has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered one year of complimentary identity protection and credit monitoring services through Experian to all affected individuals.
Multiple major organisations have reported breaches tied to this vulnerability, including GlobalLogic (Hitachi Group), Cox Enterprises, The Washington Post, Allianz UK, Sato Corporation, Envoy Air, and NHS England, all of which experienced various levels of data exposure or unauthorised access.
Oracle released emergency patches to fix the zero-day flaw and urged customers to update immediately, though some of the initial fixes proved ineffective and required additional urgent updates.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543