PAREXEL INTERNATIONAL, INC.
bd_7678d521c76b2a6b · schema v1 · pii pii-v1
Full breach record for PAREXEL INTERNATIONAL, INC. →Parexel International disclosed a security incident involving a third-party vendor, Oracle. On October 4, 2025, Parexel detected suspicious activity in its Oracle OCI E-Business Suite environment. The incident stemmed from a zero-day exploit in Oracle's cloud infrastructure, announced by Oracle on October 5, 2025. The breach window is cited as August 9, 2025, to October 5, 2025. Affected data includes names, dates of birth, financial account numbers, payment card numbers, and social security/national ID numbers of employees. Parexel disconnected the affected system, applied patches, and is offering 24 months of identity monitoring to affected individuals.
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0288fc926d272d31Texas State AGfiled 2025-12-17Candidate
- bd_5cf5bdff6a9f9cdeNew Hampshire State AGfiled 2025-12-17Verified
- bd_5fa13ba676bcd123Montana State AGfiled 2025-12-17Verified
- bd_937062a523a21f33Vermont State AGfiled 2025-12-17Verified
Show 2 more filings ↓Show fewer ↑
- bd_a687dffb1206e0f0Maine State AGfiled 2025-12-17Verified
- bd_a9becd46a7821791Indiana State AGfiled 2025-12-17Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-615908
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 17, 2025
- Raw hash
- 7886069dbc48f3472034c42d1bea7c0e2b861cf96d7118226effeb4f5ec677bb
Reporting entity
- Name
- PAREXEL INTERNATIONAL, INC.norm: parexel international
Victim entity
- Name
- PAREXEL INTERNATIONAL, INC.norm: parexel international
Incident
- Discovered
- Oct 4, 2025
- Materiality determined
- —
- Notification sent
- Dec 17, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Oracle
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- CA 60-day late · 74d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 4, 2025→ Notified: Dec 17, 202574d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.