PAREXEL INTERNATIONAL, INC.
ent_019e1f28e28cc965386c5958c92cb9a3
Disclosures
10
State AG · 10 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
65,587
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PAREXEL INTERNATIONAL, INC.
- Normalized
- parexel international— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900PHGVI5379Z9791
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- Texas State AGas victim2025-12-17
Parexel International, LLC (“Parexel”) based in Raleigh, North Carolina, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-11-20 and reported on 2025-12-17. 1,203 Texas residents were affected. 65,587 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Financial Information (e.g. account number, credit or debit card number);Date of Birth. Consumers were notified via U.S. Mail.
- Massachusetts State AGas victim2025-12-17
Parexel International, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-12-17. 5,259 Massachusetts residents were affected.
- New Hampshire State AGas victim2025-12-17
Parexel International, LLC detected a security incident on October 4, 2025, involving a zero-day vulnerability in Oracle E-Business Suite. An unauthorized individual accessed and potentially acquired employee data, including names, SSNs, dates of birth, and financial account numbers. The incident affected 1,151 New Hampshire residents. Parexel applied patches, engaged forensic experts, and notified law enforcement. Notifications were sent on December 17, 2025, with 24 months of credit monitoring offered.
- Montana State AGas victim2025-12-17
Parexel International, LLC notified Montana residents of a security incident involving a third-party vendor (Oracle) hosting its Oracle E-Business Suite. A zero-day exploit on October 4, 2025, led to unauthorized access. Affected data included names, DOBs, SSNs, and financial account numbers. Parexel disconnected the environment, applied patches, and engaged forensic experts.
- California State AGas victim2025-12-17
Parexel International disclosed a security incident involving a third-party vendor, Oracle. On October 4, 2025, Parexel detected suspicious activity in its Oracle OCI E-Business Suite environment. The incident stemmed from a zero-day exploit in Oracle's cloud infrastructure, announced by Oracle on October 5, 2025. The breach window is cited as August 9, 2025, to October 5, 2025. Affected data includes names, dates of birth, financial account numbers, payment card numbers, and social security/national ID numbers of employees. Parexel disconnected the affected system, applied patches, and is offering 24 months of identity monitoring to affected individuals.
- Nebraska State AGas victim2025-12-17
Parexel International LLC reported a security incident involving a third-party vendor (Oracle) hosting its Oracle E-Business Suite. On October 4, 2025, suspicious activity was detected stemming from a zero-day exploit in Oracle's cloud infrastructure. The incident involved unauthorized access to files containing personal information, including names, dates of birth, financial account numbers, payment card numbers, and Social Security numbers. Parexel disconnected the affected environment, applied the vendor's patch, and offered 24 months of complimentary credit monitoring to affected individuals. Notices were sent on December 17, 2025.
- Vermont State AGas victim2025-12-17
Parexel International notified consumers of a data breach involving a third-party vendor (Oracle) on October 4, 2025. A zero-day exploit in Oracle's cloud infrastructure allowed unauthorized access to files containing personal information (names, DOBs, SSNs, financial data). Parexel disconnected the environment, applied patches, and offered 24 months of credit monitoring.
- Maine State AGas victim2025-12-17
Parexel International, LLC reported a data breach affecting 158 Maine residents. The incident involved a zero-day exploit against Oracle's cloud infrastructure (OCI E-Business Suite) hosted by a third-party vendor. Unauthorized access occurred between August 9 and October 5, 2025, and was discovered on October 4, 2025. Affected data included names, DOBs, financial account numbers, payment card numbers, and SSNs. Parexel disconnected the environment, applied the patch, and offered 24 months of identity protection services.
- Indiana State AGas victim2025-12-17
Parexel International LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-10-04 and was reported on 2025-12-17. 213 Indiana residents were affected.
- Illinois State AGas victim2025-12-01
PAREXEL INTERNATIONAL, LLC filed a data-breach notice with the Illinois Attorney General in December 2025 (case 25-12-665). The register records the breach as discovered on November 20, 2025. Personal information types reported: financial account number, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Supply-chain cascadesreviewed and confirmed
- PAREXEL INTERNATIONAL, INC.’s filing is one of at least 7 in the ORACLE CORPORATION supply-chain incident (2025).