HackingVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
The University of Phoenix, Inc.
bd_76c4b059c21b7a70 · schema v1 · pii pii-v1
Full breach record for The University of Phoenix, Inc. →University of Phoenix, Inc. disclosed a cybersecurity incident involving an Oracle E-Business Suite (EBS) vulnerability. An unauthorized third party exploited a previously unknown vulnerability (0-day) in Oracle EBS to exfiltrate data between August 13 and 22, 2025. The University learned of the incident on November 21, 2025. Affected data may include names and Social Security numbers. The University engaged third-party cybersecurity firms, notified law enforcement, and offered complimentary identity protection services through IDX.
This filing is one of 12 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_3d18365ebdc6078fIndiana State AGfiled 2025-12-22Verified
- bd_5c3c3d94680bea80Texas State AGfiled 2025-12-22Verified
- bd_b8bb5487f6611341South Carolina State AGfiled 2025-12-22Verified
- bd_fac6b9ef2dd646f4New Hampshire State AGfiled 2025-12-22Verified
Show 6 more filings ↓Show fewer ↑up to 20d gap
- bd_07f2680cb5c0bb72Oregon State AGfiled 2025-12-21(1d gap)Verified
- bd_296734ddcf83ab6aIowa State AGfiled 2025-12-21(1d gap)Verified
- bd_2a49899925132de7California State AGfiled 2025-12-21(1d gap)Verified
- bd_dc51c3e1baef7969Washington State AGfiled 2025-12-21(1d gap)Verified
- bd_fa3d3b455f65bfaaMaine State AGfiled 2025-12-21(1d gap)Verified
- bd_4f43b0b314a5713fSEC 8-Kfiled 2025-12-02(20d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2026/01/University-of-Phoenix-Regulatory-Notice-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2025
- Raw hash
- 8a27136507bd32f15f99ab7dd1f4668f248e522105ae2c2ba3418ac7fa777f61
Reporting entity
- Name
- The University of Phoenix, Inc.norm: the university of phoenix
Victim entity
- Name
- The University of Phoenix, Inc.norm: the university of phoenix
Incident
- Discovered
- Nov 21, 2025
- Materiality determined
- —
- Notification sent
- Dec 22, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.