Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

macOS Flaw Lets Standard Users Disable EDR and MDM

June 26, 2026

Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

June 26, 2026

Major Increase in Ransomware Attacks Targeting Europe, Warns Report

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Clop Ransomware Group Linked to 3.5m University of Phoenix Breach
News

Clop Ransomware Group Linked to 3.5m University of Phoenix Breach

Team-CWDBy Team-CWDDecember 24, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A data breach affecting nearly 3.5 million individuals has been disclosed by the University of Phoenix after attackers gained unauthorized access to its systems during the summer.

The incident involved the theft of sensitive personal and financial information belonging to current and former students, staff, faculty and suppliers.

The University of Phoenix, a private for-profit institution headquartered in Phoenix, Arizona, said the breach stemmed from an attack on its Oracle E-Business Suite (EBS) financial application.

Investigators determined that the intrusion occurred between August 13 and 22 2025, but it was not detected until November 21, one day after the university was named on the Clop ransomware gang’s data leak site.

In early December, the university published a notice on its website and its parent company, Phoenix Education Partners, filed an 8-K with the US Securities and Exchange Commission.

Notification letters submitted to the Maine Attorney General’s Office and affected individuals on Monday confirmed that 3,489,274 individuals were affected, including 9131 Maine residents.

The compromised data included:

The university said the information was accessed without authorization but noted that bank details were obtained “without means of access.”

A Broader Campaign

The attack is believed to be part of a broader campaign in which the Clop ransomware group exploited a zero-day vulnerability in Oracle E-Business Suite, tracked as CVE-2025-61882. The campaign, which surfaced publicly in early October, has targeted more than 100 organizations across multiple sectors.

“According to our data, this is the fourth-largest ransomware attack in the world this year (based on records affected),” Rebecca Moody, head of data research at Comparitech, said.

“It highlights the ongoing threat that companies face via ransomware – and not just via attacks on their own systems. Attacks on third parties like Oracle often give hackers access to a multitude of companies (and their data) via one central source.”

Read more on Oracle E-Business Suite cybersecurity risks: Hackers Target Unpatched Flaws in Oracle E-Business Suite

While Clop has claimed responsibility, some security researchers have been reluctant to place attribution solely with the FIN11 threat group.

Other US universities confirmed to be affected by Oracle EBS breaches include Harvard University, the University of Pennsylvania and Dartmouth College.

Despite the scale of the incident, no University of Phoenix data has appeared publicly at the time of writing, even as attackers released large volumes of files allegedly stolen from other victims.

Education Remains a Target Sector

The University of Phoenix said it is offering free identity protection services to affected individuals. These include 12 months of credit monitoring, identity theft recovery assistance, dark web monitoring and a $1m fraud reimbursement policy.

“I would urge any individuals affected by this breach to take advantage of the university’s offer of free identity protection services,” said Chris Hauk, consumer privacy champion at Pixel Privacy.

“This will give them a leg up in detecting if bad actors are attempting to use the data gathered from the breach for nefarious purposes.”

Security leaders say the incident reflects systemic weaknesses across higher education.

“This breach underscores a troubling pattern we’ve seen throughout 2025,” explained Ensar Seker, CISO of SOCRadar.

“Threat actors like Clop continue to weaponize zero-day vulnerabilities and mass data exfiltration campaigns against large, centralized educational platforms.”

The breach ranks among the most significant education sector incidents reported in 2025. It also highlights the continued appeal of universities as targets for cybercriminals seeking access to extensive repositories of personal and financial data.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE
Next Article Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats
Team-CWD
  • Website

Related Posts

News

macOS Flaw Lets Standard Users Disable EDR and MDM

June 26, 2026
News

Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

June 26, 2026
News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Can password managers get hacked? Here’s what to know

November 14, 2025

How cybercriminals are targeting content creators

November 26, 2025

Here’s what you should know

February 6, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.