HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
The University of Phoenix, Inc.
bd_2a49899925132de7 · schema v1 · pii pii-v1
Full breach record for The University of Phoenix, Inc. →University of Phoenix, Inc. disclosed a cybersecurity incident where an unauthorized third party exploited a previously unknown vulnerability in Oracle E-Business Suite to exfiltrate data between August 13 and 22, 2025. The university discovered the incident on November 21, 2025. Affected data may include names and Social Security numbers. The university engaged third-party cybersecurity firms, notified law enforcement, and is offering identity protection services.
California clockDiscovered Nov 21, 2025 → Notified Dec 22, 202531d ✓ CA 60-day OK4 weeks discovery → filing
This filing is one of 12 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_07f2680cb5c0bb72Oregon State AGfiled 2025-12-21Verified
- bd_296734ddcf83ab6aIowa State AGfiled 2025-12-21Verified
- bd_dc51c3e1baef7969Washington State AGfiled 2025-12-21Verified
- bd_fa3d3b455f65bfaaMaine State AGfiled 2025-12-21Verified
Show 6 more filings ↓Show fewer ↑up to 19d gap
- bd_3d18365ebdc6078fIndiana State AGfiled 2025-12-22(1d gap)Verified
- bd_5c3c3d94680bea80Texas State AGfiled 2025-12-22(1d gap)Verified
- bd_76c4b059c21b7a70Delaware State AGfiled 2025-12-22(1d gap)Verified
- bd_b8bb5487f6611341South Carolina State AGfiled 2025-12-22(1d gap)Verified
- bd_fac6b9ef2dd646f4New Hampshire State AGfiled 2025-12-22(1d gap)Verified
- bd_4f43b0b314a5713fSEC 8-Kfiled 2025-12-02(19d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-616134
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 21, 2025
- Raw hash
- cecf171aa9f6d976cd79cfe4ba5d0dd925bff6b0562d577bdf3acb9ffe6184a6
Reporting entity
- Name
- The University of Phoenix, Inc.norm: the university of phoenix
Victim entity
- Name
- The University of Phoenix, Inc.norm: the university of phoenix
Incident
- Discovered
- Nov 21, 2025
- Materiality determined
- —
- Notification sent
- Dec 22, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 31d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 21, 2025→ Notified: Dec 22, 202531d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.