The University of Phoenix, Inc.
bd_fac6b9ef2dd646f4 · schema v1 · pii pii-v1
Full breach record for The University of Phoenix, Inc. →2 incidents on fileUniversity of Phoenix, Inc. notified the New Hampshire Attorney General of a data security incident involving an Oracle E-Business Suite vulnerability. Unauthorized access occurred between August 13 and 22, 2025, when an attacker exploited a previously unknown vulnerability to exfiltrate data. The incident affected approximately 6,661 New Hampshire residents, exposing names, dates of birth, Social Security numbers, and bank account/routing numbers. Notifications to affected individuals began on December 22, 2025, offering credit monitoring and identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 13, 2025
Begins
Nov 21, 2025
Discovered
Dec 22, 2025
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Indiana State AGbd_3d18365ebdc6078f2025-12-22Verified
- Texas State AGbd_5c3c3d94680bea802025-12-22Verified
- Nebraska State AGbd_65849a27efab9be32025-12-22Verified
- Delaware State AGbd_76c4b059c21b7a702025-12-22Verified
Show 6 more filings ↓Show fewer ↑up to 10d gap
- South Carolina State AGbd_b8bb5487f66113412025-12-22Verified
- Oregon State AGbd_07f2680cb5c0bb722025-12-21 · +1dVerified
- Massachusetts State AGbd_0f1e0ada220db05b2025-12-21 · +1dVerified
- Iowa State AGbd_296734ddcf83ab6a2025-12-21 · +1dVerified
- California State AGbd_2a49899925132de72025-12-21 · +1dVerified
- Illinois State AGbd_26bf80a345c196ab2026-01-01 · +10dVerified
Showing first 10 of 14 linked disclosures.
Filing propagation · 11 filings · 11 states
View merged incident ↗Pattern: first filing Dec 21 (OR), last Jan 1 (IL) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 14 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.