
The University of Phoenix recently disclosed a major data breach in which threat actors leveraged a zero-day flaw in Oracle’s E-Business Suite, compromising sensitive personal data belonging to several students and staff.
In a data security incident notice on its website, UoPX said that on November 21, it became aware of a breach in which threat actors exploited a previously unknown vulnerability in the Oracle EBS system the university uses to manage critical internal operations, including human resources, finance, and other functions.
Oracle E-Business Suite is a widely used ERP platform for managing functions like HR, finance, and supply chain. Clop exploited a critical zero-day flaw—primarily CVE-2025-61882, and possibly CVE-2025-61884—in the EBS BI Publisher component, allowing them to remotely execute arbitrary code without authentication.
An investigation into the incident revealed that “like many other organisations, including other colleges and universities, an unauthorised third-party exploited a previously unknown software vulnerability in Oracle EBS to exfiltrate certain data within the University’s Oracle EBS environment.
“We believe that the unauthorised third-party obtained certain personal information, including names and contact information, dates of birth, social security numbers, and bank account and routing numbers with respect to numerous current and former students, employees, faculty and suppliers accessed without authorisation,” the University said.
UoPX added that it promptly applied the Oracle EBS software patches released in October 2025 to remediate the vulnerability. It also notified the appropriate law-enforcement authorities about the incident and will continue to cooperate with their ongoing investigation.
The University’s parent company, Phoenix Education Partners, filed a Form 8-K with the Securities and Exchange Commission (SEC), confirming the data security incident and stating that “the Company believes the incident will not have a material adverse effect on its business operations or student programming.”
The institution advised affected individuals to monitor their credit, account, and benefit statements and report any suspicious activity to law enforcement. It has also provided complimentary identity protection and credit monitoring services through IDX.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543