HackingVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
The University of Phoenix, Inc.
bd_b8bb5487f6611341 · schema v1 · pii pii-v1
Full breach record for The University of Phoenix, Inc. →University of Phoenix, Inc. notified South Carolina residents of a cybersecurity incident involving an Oracle E-Business Suite vulnerability exploited between August 13-22, 2025. The attacker exfiltrated names and potentially Social Security numbers. The incident was discovered on November 21, 2025. The University engaged third-party cybersecurity firms, notified law enforcement, and is offering complimentary identity protection services.
This filing is one of 12 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_3d18365ebdc6078fIndiana State AGfiled 2025-12-22Verified
- bd_5c3c3d94680bea80Texas State AGfiled 2025-12-22Verified
- bd_76c4b059c21b7a70Delaware State AGfiled 2025-12-22Verified
- bd_fac6b9ef2dd646f4New Hampshire State AGfiled 2025-12-22Verified
Show 6 more filings ↓Show fewer ↑up to 20d gap
- bd_07f2680cb5c0bb72Oregon State AGfiled 2025-12-21(1d gap)Verified
- bd_296734ddcf83ab6aIowa State AGfiled 2025-12-21(1d gap)Verified
- bd_2a49899925132de7California State AGfiled 2025-12-21(1d gap)Verified
- bd_dc51c3e1baef7969Washington State AGfiled 2025-12-21(1d gap)Verified
- bd_fa3d3b455f65bfaaMaine State AGfiled 2025-12-21(1d gap)Verified
- bd_4f43b0b314a5713fSEC 8-Kfiled 2025-12-02(20d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Letter%20-%20University%20of%20Phoenix%2C%20Inc..pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2025
- Raw hash
- 40e26cf8ebd028e4e4b74977be590ff76c26c3d0b4fc094480ca901bf277ceaa
Reporting entity
- Name
- The University of Phoenix, Inc.norm: the university of phoenix
Victim entity
- Name
- The University of Phoenix, Inc.norm: the university of phoenix
Incident
- Discovered
- Nov 21, 2025
- Materiality determined
- —
- Notification sent
- Dec 22, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.