HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
PAREXEL INTERNATIONAL, INC.
bd_937062a523a21f33 · schema v1 · pii pii-v1
Full breach record for PAREXEL INTERNATIONAL, INC. →Parexel International notified consumers of a data breach involving a third-party vendor (Oracle) on October 4, 2025. A zero-day exploit in Oracle's cloud infrastructure allowed unauthorized access to files containing personal information (names, DOBs, SSNs, financial data). Parexel disconnected the environment, applied patches, and offered 24 months of credit monitoring.
Vermont clock✗ VT AG >45 bday11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0288fc926d272d31Texas State AGfiled 2025-12-17Candidate
- bd_5cf5bdff6a9f9cdeNew Hampshire State AGfiled 2025-12-17Verified
- bd_5fa13ba676bcd123Montana State AGfiled 2025-12-17Verified
- bd_7678d521c76b2a6bCalifornia State AGfiled 2025-12-17Verified
Show 2 more filings ↓Show fewer ↑
- bd_a687dffb1206e0f0Maine State AGfiled 2025-12-17Verified
- bd_a9becd46a7821791Indiana State AGfiled 2025-12-17Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-17-parexel-international-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 17, 2025
- Raw hash
- d3b945124cbe11e653bd1caa56d53d685d208aa83ff4ee26eb012549d91d159a
Reporting entity
- Name
- PAREXEL INTERNATIONAL, INC.norm: parexel international
Victim entity
- Name
- PAREXEL INTERNATIONAL, INC.norm: parexel international
Incident
- Discovered
- Oct 4, 2025
- Materiality determined
- —
- Notification sent
- Dec 17, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with the Office of the Vermont Attorney General
- Third party
- via Oracle
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.