University of Phoenix discloses data breach after Oracle hack
嗯,用户让我用中文总结一下这篇文章,控制在一百个字以内。首先,我需要通读整篇文章,抓住主要信息。文章讲的是凤凰城大学在2025年8月被Clop勒索软件团伙攻击,利用Oracle E-Business Suite的零日漏洞窃取了大量敏感数据,包括学生、员工和供应商的信息。同时,还提到其他美国大学也受到了类似攻击。 接下来,我要确定总结的关键点:凤凰城大学、数据泄露、Clop团伙、零日漏洞、受影响的人群。然后,把这些信息浓缩到100字以内,确保语言简洁明了。 可能会遇到的问题是如何在有限的字数内涵盖所有重要信息。需要优先保留最重要的部分:事件的时间、机构名称、攻击者、漏洞类型以及受影响的群体。其他细节如具体日期或受影响人数可以适当简化或省略。 最后,检查总结是否符合要求:中文、100字以内、直接描述内容,不需要特定开头。确保没有遗漏关键信息,并且表达清晰。 </think> 凤凰城大学在2025年8月因Clop勒索软件团伙利用Oracle E-Business Suite的零日漏洞遭受数据泄露,涉及学生、员工及供应商的敏感信息。该事件是针对多个美国大学和企业的系列攻击之一。 2025-12-3 13:30:20 Author: www.bleepingcomputer.com(查看原文) 阅读量:9 收藏

University of Phoenix

The University of Phoenix (UoPX) has joined a growing list of U.S. universities breached in a Clop data theft campaign targeting vulnerable Oracle E-Business Suite instances in August 2025.

Founded in 1976 and headquartered in Phoenix, Arizona, UoPX is a private for-profit university with nearly 3,000 academic staff and over 100,000 enrolled students.

The university disclosed the data breach on its official website on Tuesday, while its parent company, Phoenix Education Partners, filed an 8-K form with the U.S. Securities and Exchange Commission (SEC).

UoPX said it detected the incident on November 21 (after the extortion group added it to its data leak site) and noted that the attackers exploited a zero-day vulnerability in the Oracle E-Business Suite (EBS) financial application to steal a wide range of sensitive personal and financial information belonging to students, staff, and suppliers.

"We believe that the unauthorized third-party obtained certain personal information, including names and contact information, dates of birth, social security numbers, and bank account and routing numbers with respect to numerous current and former students, employees, faculty and suppliers was accessed without authorization," the school said.

"We continue to review the impacted data and will provide the required notifications to affected individuals and regulatory entities. Affected individuals will soon receive a letter via US Mail outlining the details of the incident and next steps to take."

Andrea Smiley, Vice President for Public Relations at University of Phoenix, told BleepingComputer that UoPX is "reviewing the impacted data and will provide the required notifications to affected individuals and regulatory entities." However, Smiley didn't share any further details about the breach, including which cybercrime operation was behind the attack or the total number of individuals affected.

University of Phoenix entry on Clop's leak site
University of Phoenix entry on Clop's leak site (BleepingComputer)

​Although UoPX has yet to attribute the incident to a specific cybercrime group, based on the details shared so far, the breach is part of a Clop ransomware gang extortion campaign in which the gang has exploited a zero-day flaw (CVE-2025-61882) to steal sensitive documents from many victims' Oracle EBS platforms since early August 2025.

As part of the same series of data theft attacks, Clop has also targeted other universities in the United States, including Harvard University and the University of Pennsylvania, which have also confirmed Oracle EBS breaches impacting their students and staff.

The extortion group also compromised the Oracle EBS instances of dozens of companies worldwide, including GlobalLogic, Logitech, The Washington Post, and the American Airlines subsidiary Envoy Air, and leaked the stolen data on its dark web site.

In the past, Clop was also behind data theft campaigns targeting GoAnywhere MFT, Accellion FTA, Cleo, and MOVEit Transfer customers, the latter affecting more than 2,770 organizations.

Since late October, the systems of several U.S. universities have also been breached in a series of voice phishing attacks, with Harvard University, University of Pennsylvania, and Princeton University disclosing that the attackers breached systems used for development and alumni activities to steal the personal information of donors, staff, students, alumni, and faculty.

Update December 03, 10:16 EST: Added statement from University of Phoenix.

tines

Break down IAM silos like Bitpanda, KnowBe4, and PathAI

Broken IAM isn't just an IT problem - the impact ripples across your whole business.

This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.


文章来源: https://www.bleepingcomputer.com/news/security/university-of-phoenix-discloses-data-breach-after-oracle-hack/
如有侵权请联系:admin#unsafe.sh