HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
The Trustees of the University of Pennsylvania
bd_194bd163b527a335 · schema v1 · pii pii-v1
Full breach record for The Trustees of the University of Pennsylvania →The University of Pennsylvania notified California residents of a data breach involving a third-party Oracle E-Business Suite application. A previously unknown vulnerability (zero-day) in Oracle software allowed unauthorized access to data between August 9 and August 11, 2025. Affected data included Social Security numbers, names, addresses, and bank account information. The University engaged cybersecurity experts, notified law enforcement, applied patches, and is offering 24 months of credit monitoring.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_20d98f86cadb1602Leak Siteshinyhuntersfiled 2026-02-04(65d gap)Verified
Regulatory filings (6) · sorted by filing gap
- bd_1fae715254418c00Montana State AGfiled 2025-12-01Verified
- bd_3340eceed80aa4a6Iowa State AGfiled 2025-12-01Verified
- bd_dcf68884b841a7d5Washington State AGfiled 2025-12-01Verified
- bd_e679c6a24510eaf9Texas State AGfiled 2025-12-03(2d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 135d gap
- bd_52860701b7a833ffOregon State AGfiled 2025-12-22(21d gap)Verified
- bd_5fa5e741d0d86224Washington State AGfiled 2026-04-15(135d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-614893
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 1, 2025
- Raw hash
- 3c58e0135b4e7367b0938ff4f7c5e1cc6ec6be217b9c2ec233d034b0a4f68be0
Reporting entity
- Name
- The Trustees of the University of Pennsylvanianorm: the trustees of the university of pennsylvania
Victim entity
- Name
- The Trustees of the University of Pennsylvanianorm: the trustees of the university of pennsylvania
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Dec 1, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Cooperating with an ongoing federal law enforcement investigation
- Third party
- via Oracle
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.