The University of Phoenix, Inc.
bd_76c4b059c21b7a70 · schema v1 · pii pii-v1
Full breach record for The University of Phoenix, Inc. →2 incidents on fileUniversity of Phoenix, Inc. disclosed a cybersecurity incident involving an Oracle E-Business Suite (EBS) vulnerability. An unauthorized third party exploited a previously unknown vulnerability (0-day) in Oracle EBS to exfiltrate data between August 13 and 22, 2025. The University learned of the incident on November 21, 2025. Affected data may include names and Social Security numbers. The University engaged third-party cybersecurity firms, notified law enforcement, and offered complimentary identity protection services through IDX.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 13, 2025
Begins
Nov 21, 2025
Discovered
Dec 22, 2025
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Indiana State AGbd_3d18365ebdc6078f2025-12-22Verified
- Texas State AGbd_5c3c3d94680bea802025-12-22Verified
- Nebraska State AGbd_65849a27efab9be32025-12-22Verified
- South Carolina State AGbd_b8bb5487f66113412025-12-22Verified
Show 6 more filings ↓Show fewer ↑up to 10d gap
- New Hampshire State AGbd_fac6b9ef2dd646f42025-12-22Verified
- Oregon State AGbd_07f2680cb5c0bb722025-12-21 · +1dVerified
- Massachusetts State AGbd_0f1e0ada220db05b2025-12-21 · +1dVerified
- Iowa State AGbd_296734ddcf83ab6a2025-12-21 · +1dVerified
- California State AGbd_2a49899925132de72025-12-21 · +1dVerified
- Illinois State AGbd_26bf80a345c196ab2026-01-01 · +10dVerified
Showing first 10 of 14 linked disclosures.
Filing propagation · 11 filings · 11 states
View merged incident ↗Pattern: first filing Dec 21 (OR), last Jan 1 (IL) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 14 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.