HackingVulnerability ExploitCL0pZero-DayData ExfiltratedData PublishedRansom DemandedTargetedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Harvard University
bd_0dfa068a1f7e8d87 · schema v1 · pii pii-v1
Full breach record for Harvard University →Harvard University notified the New Hampshire Attorney General on February 6, 2026, regarding a data incident involving the CL0p threat actor. The actor exploited a zero-day vulnerability in an Oracle E-Business Suite application between August 9 and August 20, 2025, to exfiltrate and publish data. The breach affected 4 New Hampshire residents, exposing names, addresses, and Social Security numbers. Harvard engaged forensic experts, applied Oracle's patch, and is providing two years of credit monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/harvard-university-20260206.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 6, 2026
- Raw hash
- d03519306a166f3c5a700b3eada9e1accd2aa3f1a32889c5177953700c10eef8
Reporting entity
- Name
- Harvard Universitynorm: harvard university
Victim entity
- Name
- Harvard Universitynorm: harvard university
Incident
- Discovered
- Sep 29, 2025
- Materiality determined
- —
- Notification sent
- Feb 6, 2026
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access· CL0p
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1486 Data Encrypted for Impact
- Threat actor
- CL0pExternalFinancial
- Regulator citations
- sending notices to New Hampshire residents advising them of a data incidentnotifying the New Hampshire Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(130 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.