HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)Employee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
PAREXEL INTERNATIONAL, INC.
bd_5cf5bdff6a9f9cde · schema v1 · pii pii-v1
Full breach record for PAREXEL INTERNATIONAL, INC. →Parexel International, LLC reported a security incident involving its Oracle E-Business Suite instance hosted by Oracle. On October 4, 2025, an unauthorized individual exploited a zero-day vulnerability to access employee data, including names, SSNs, and financial account numbers. 1,151 New Hampshire residents were affected. Parexel applied Oracle's patch, notified law enforcement, and began mailing notifications with 24 months of credit monitoring on December 17, 2025.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0288fc926d272d31Texas State AGfiled 2025-12-17Candidate
- bd_5fa13ba676bcd123Montana State AGfiled 2025-12-17Verified
- bd_7678d521c76b2a6bCalifornia State AGfiled 2025-12-17Verified
- bd_937062a523a21f33Vermont State AGfiled 2025-12-17Verified
Show 2 more filings ↓Show fewer ↑
- bd_a687dffb1206e0f0Maine State AGfiled 2025-12-17Verified
- bd_a9becd46a7821791Indiana State AGfiled 2025-12-17Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/parexel-international-oracle-e-business-suite-20251217.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 17, 2025
- Raw hash
- d56e507dbf66dc0e2df22f29912798a0c8f02757afd106ddc362386e43c35cac
Reporting entity
- Name
- PAREXEL INTERNATIONAL, INC.norm: parexel international
Victim entity
- Name
- PAREXEL INTERNATIONAL, INC.norm: parexel international
Incident
- Discovered
- Oct 4, 2025
- Materiality determined
- —
- Notification sent
- Dec 17, 2025
- Affected individuals
- 1,151
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.