ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Zero-Day Oracle Flaw Leads to Major Data Breach at University of Phoenix

The University of Phoenix recently disclosed a major data breach in which threat actors leveraged a zero-day flaw in Oracle’s E-Business Suite, compromising sensitive personal data belonging to several students and staff.

 

In a data security incident notice on its website, UoPX said that on November 21, it became aware of a breach in which threat actors exploited a previously unknown vulnerability in the Oracle EBS system the university uses to manage critical internal operations, including human resources, finance, and other functions.

 

Oracle E-Business Suite is a widely used ERP platform for managing functions like HR, finance, and supply chain. Clop exploited a critical zero-day flaw—primarily CVE-2025-61882, and possibly CVE-2025-61884—in the EBS BI Publisher component, allowing them to remotely execute arbitrary code without authentication.

 

An investigation into the incident revealed that “like many other organisations, including other colleges and universities, an unauthorised third-party exploited a previously unknown software vulnerability in Oracle EBS to exfiltrate certain data within the University’s Oracle EBS environment.

 

“We believe that the unauthorised third-party obtained certain personal information, including names and contact information, dates of birth, social security numbers, and bank account and routing numbers with respect to numerous current and former students, employees, faculty and suppliers accessed without authorisation,” the University said.

 

UoPX added that it promptly applied the Oracle EBS software patches released in October 2025 to remediate the vulnerability. It also notified the appropriate law-enforcement authorities about the incident and will continue to cooperate with their ongoing investigation.

 

The University’s parent company, Phoenix Education Partners, filed a Form 8-K with the Securities and Exchange Commission (SEC), confirming the data security incident and stating that “the Company believes the incident will not have a material adverse effect on its business operations or student programming.”

 

The institution advised affected individuals to monitor their credit, account, and benefit statements and report any suspicious activity to law enforcement. It has also provided complimentary identity protection and credit monitoring services through IDX.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543