HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
tulane.edu
bd_99d1b59303184ccb · schema v1 · pii pii-v1
Full breach record for tulane.edu →Tulane University notified the New Hampshire Attorney General of a data security incident involving a zero-day vulnerability in Oracle’s E-Business Suite. Unauthorized access occurred on August 10, 2025, exposing names, Social Security numbers, and direct deposit banking information of current and former employees and their dependents. Tulane notified law enforcement, applied patches, and began mailing notifications on April 2, 2026, offering one year of credit monitoring to 170 affected New Hampshire residents.
Leak gap clock⏱ Leak >90d39 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 171 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_50db809f15fefd3fVermont State AGfiled 2026-05-12Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/tulane-university-20260512.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 12, 2026
- Raw hash
- ef66e53f645bcbe17b049f9053849eed30c64ebbdb0a83db26007123929b4ded
Reporting entity
- Name
- tulane.edunorm: tulaneedu
- Domain
- tulane.edu
Victim entity
- Name
- tulane.edunorm: tulaneedu
- Domain
- tulane.edu
Incident
- Discovered
- Aug 10, 2025
- Materiality determined
- —
- Notification sent
- Apr 2, 2026
- Affected individuals
- 170
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 39 weeks(275 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.