The University of Phoenix, Inc.
ent_019e1f24a36ccb684c22af3b51477138
Disclosures
12
State AG · SEC 8-K · 12 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
3,500,000
as filed · State AG WI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The University of Phoenix, Inc.
- Normalized
- the university of phoenix— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900ZYS0RDYLMNIU84
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- Phoenix Education Partners, Inc.— per SEC Exhibit 21 filing
Disclosure history (12)newest first
- 🏎️Indiana State AGas victim2025-12-22
University of Phoenix Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-13 and was reported on 2025-12-22. 56,568 Indiana residents were affected. 3,489,274 individuals affected in total.
- ⭐Texas State AGas victim2025-12-22
University of Phoenix, Inc. based in Phoenix, Arizona, a educational institution entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-11-21 and reported on 2025-12-22. 304,393 Texas residents were affected. 3,489,274 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Financial Information (e.g. account number, credit or debit card number);Date of Birth. Consumers were notified via U.S. Mail.
- 💎Delaware State AGas victim2025-12-22
University of Phoenix, Inc. disclosed a cybersecurity incident involving an Oracle E-Business Suite (EBS) vulnerability. An unauthorized third party exploited a previously unknown vulnerability (0-day) in Oracle EBS to exfiltrate data between August 13 and 22, 2025. The University learned of the incident on November 21, 2025. Affected data may include names and Social Security numbers. The University engaged third-party cybersecurity firms, notified law enforcement, and offered complimentary identity protection services through IDX.
- 🌴South Carolina State AGas victim2025-12-22
University of Phoenix, Inc. notified South Carolina residents of a cybersecurity incident involving an Oracle E-Business Suite vulnerability exploited between August 13-22, 2025. The attacker exfiltrated names and potentially Social Security numbers. The incident was discovered on November 21, 2025. The University engaged third-party cybersecurity firms, notified law enforcement, and is offering complimentary identity protection services.
- ⛰️New Hampshire State AGas victim2025-12-22
University of Phoenix, Inc. notified the New Hampshire Attorney General of a data security incident involving an Oracle E-Business Suite vulnerability. Unauthorized access occurred between August 13 and 22, 2025, when an attacker exploited a previously unknown vulnerability to exfiltrate data. The incident affected approximately 6,661 New Hampshire residents, exposing names, dates of birth, Social Security numbers, and bank account/routing numbers. Notifications to affected individuals began on December 22, 2025, offering credit monitoring and identity protection services.
- 🦫Oregon State AGas victim2025-12-21
University of Phoenix, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2025-12-21. The breach occurred during 8/13/2025 - 8/22/2025. The breach was discovered on 11/21/2025. 3,489,274 individuals were affected. Notice was sent on 1/1/0001.
- 🌽Iowa State AGas victim2025-12-21
University of Phoenix, a education sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2025-12-21.
- 🐻California State AGas victim2025-12-21
University of Phoenix, Inc. disclosed a cybersecurity incident where an unauthorized third party exploited a previously unknown vulnerability in Oracle E-Business Suite to exfiltrate data between August 13 and 22, 2025. The university discovered the incident on November 21, 2025. Affected data may include names and Social Security numbers. The university engaged third-party cybersecurity firms, notified law enforcement, and is offering identity protection services.
- 🌲Washington State AGas victim2025-12-21
University of Phoenix, Inc., a education sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2025-11-21 and filed notice on 2025-12-21. 64,796 Washington residents were affected. 30 days elapsed between awareness and notification. 100 days to identify the breach. 0 days to contain the breach.
- 🦞Maine State AGas victim2025-12-21
University of Phoenix, Inc. experienced an external system breach discovered on November 21, 2025. The breach, which occurred on August 13, 2025, impacted 9,131 Maine residents. Affected individuals were notified on December 22, 2025, and offered identity theft protection services.
- FEDERALSEC 8-Kas victim2025-12-02
Phoenix Education Partners, Inc. (via subsidiary The University of Phoenix, Inc.) disclosed a cybersecurity incident involving the Oracle E-Business Suite (EBS). An unauthorized third party exploited a previously unknown vulnerability in Oracle EBS in August 2025 to exfiltrate data. The Company detected the incident on November 21, 2025, applied patches in October 2025, and engaged third-party cybersecurity firms. Affected data includes names, contact info, dates of birth, SSNs, and bank account/routing numbers. The investigation is ongoing.
- 🧀Wisconsin State AGas victim2025-11-21
University of Phoenix reported a data breach to the Wisconsin DATCP. The public was notified on 2025-11-21. The incident occurred on August 13-22, 2025. Data accessed: Names, contact information, dates of birth, Social Security numbers, bank account and routing numbers. 3,500,000 individuals were affected. 14,095 Wisconsin residents were affected.