University of Phoenix says 'numerous individuals' impacted by Oracle EBS breach
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户的要求是直接写文章描述,不需要特定的开头。 首先,我通读一下文章。文章主要讲的是凤凰城大学发生了数据泄露事件,黑客利用甲骨文的E-Business Suite软件漏洞入侵了他们的系统。泄露的信息包括姓名、联系方式、出生日期、社保号和银行账户信息等。此外,宾夕法尼亚大学也遭遇了同样的问题,黑客来自Clop勒索集团。 接下来,我需要提取关键信息:涉及的机构、事件原因、泄露的数据类型以及影响。同时,注意不要超过100字。 然后,组织语言,确保简洁明了。例如,“凤凰城大学和宾夕法尼亚大学遭遇数据泄露,黑客利用甲骨文软件漏洞获取了员工个人信息。”这样既涵盖了主要事件和原因,又控制在字数限制内。 最后,检查是否有遗漏的重要信息,并确保表达准确无误。 </think> 凤凰城大学和宾夕法尼亚大学遭遇数据泄露,黑客利用甲骨文软件漏洞获取了员工个人信息。 2025-12-3 18:31:12 Author: therecord.media(查看原文) 阅读量:8 收藏

The University of Phoenix became the latest U.S. educational institution to warn employees of a data breach involving a popular line of business software from Oracle.

The university’s parent company filed a notice with the Securities and Exchange Commission (SEC) on Tuesday evening saying “numerous individuals” tied to the organization had information accessed by hackers who breached the Oracle E-Business Suite software platform.

Two weeks ago, the private, for-profit school was listed on the leak site of a prominent Russian extortion group that allegedly breached dozens of organizations through a vulnerability in the Oracle platform, including Harvard University, Dartmouth College and the University of Pennsylvania. 

At the time, a University of Phoenix spokesperson told Recorded Future News that it was investigating the incident. 

In the SEC filing on Tuesday, the school said it detected the incident on November 21 and discovered that the hackers breached systems in August, gaining access to the names, contact information, dates of birth, Social Security numbers, and bank account and routing numbers of an unstated number of people. 

“The Company is one of a number of organizations, including other academic institutions, from which an unauthorized third-party exfiltrated data by exploiting a previously unknown software vulnerability in Oracle EBS,” the university disclosed. 

Despite leak site posts by the cybercriminals responsible for the hack, the University of Phoenix  said the hackers have “not publicly disseminated the data.” The school did not respond to requests for comment about how many people were impacted by the incident.

The incident will not have a material impact on business operations because the parent company — Phoenix Education Partners, Inc. — has cybersecurity insurance that will cover incident response, investigations and remediation expenses, the school said.

Penn breach

The filing by the University of Phoenix was made one day after the University of Pennsylvania told regulators in multiple states that it also suffered a data breach through the same vulnerability in Oracle software. 

The school did not say how many people were affected overall but explained that it uses Oracle EBS to “process supplier payments, reimbursements, general ledger entries, and to conduct other university business.”

The school redacted the type of information stolen from the data breach notices submitted to California, Massachusetts, Vermont and Maine. Victims are being offered two years of identity protection services.  

The University of Pennsylvania said it is now “cooperating with an ongoing federal law enforcement investigation” into the Oracle EBS attacks. The FBI and Justice Department did not respond to requests for comment about potential investigations into the string of attacks involving Oracle EBS.

The Clop extortion group claims to have stolen information from hundreds of companies through the previously unknown bug in Oracle EBS. The group has made millions over the last six years by repeatedly targeting vulnerabilities in file transfer software. 

Carl Froggett, CIO of cybersecurity company Deep Instinct, noted that schools like the University of Phoenix, Penn, Harvard and Dartmouth run on sprawling ecosystems of third-party platforms. 

“Higher-education institutions were never built to function as full-scale cyber defense operations, yet they are expected to protect research, students, employees, and operational data from both known and unknown threats,” he said.  

“The attack surface is no longer just your environment; it is every environment you depend on."

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/university-of-phoenix-data-breach
如有侵权请联系:admin#unsafe.sh