[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3v4stlzpwqpwv":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":4,"isSpamList":32,"isMalware":32,"company":33},"6a6f97dc487052d2002740f1","TulaneUniversity2025","Tulane University Data Breach","tulane-university-2025","tulane.edu","2025-08-10T00:00:00.000Z","2026-08-02T19:17:48.346Z","Unauthorized access and file acquisition through an Oracle E-Business Suite application vulnerability","https:\u002F\u002Ftulanehullabaloo.com\u002F74531\u002Fnews\u002Ftulane-employees-social-security-numbers-banking-details-exposed-in-data-breach\u002F",[14,16,17],"https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage","https:\u002F\u002Ftulane.edu\u002F",80867,"known",null,"people","Medium",[24,25,26],"Names","Social security numbers","Financial account information","\u003Cp>Tulane University is a research university based in New Orleans. Its 2025 security incident involving Oracle E‑Business Suite may have affected the personal or financial information of \u003Cstrong>80,867 people\u003C\u002Fstrong>.\u003C\u002Fp>\u003Cp>According to Tulane’s investigation, unauthorized users exploited a vulnerability in the Oracle E‑Business Suite application on August 10, 2025, accessed files, and acquired some of them. The university identified the affected files on March 12, 2026.\u003C\u002Fp>\u003Ch2>How was the incident confirmed?\u003C\u002Fh2>\u003Cp>Tulane began notifying affected employees on April 2, 2026, and student employees were among those receiving letters. The university confirmed the authenticity of the letters to its campus newspaper.\u003C\u002Fp>\u003Cp>The Texas Attorney General record reports 80,867 affected people nationwide. This is the national total in the regulator filing; the 2,992 Texas residents are an included subset of that total.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The reported data types are names, Social Security numbers, direct-deposit information, and other banking information. The regulator record classifies the financial fields under its broader financial-information category.\u003C\u002Fp>\u003Cp>Not every field should be assumed to apply to every person. Public evidence does not confirm passwords, health records, or student academic records for this event; the scope should remain limited to the disclosed employee and financial files.\u003C\u002Fp>\u003Ch2>Why do payroll and employee records matter?\u003C\u002Fh2>\u003Cp>Direct-deposit and human-resources context can help an attacker impersonate a payroll team or university administrator. Fraudulent bank-account changes, tax-document requests, or employee-portal verification messages may appear more credible.\u003C\u002Fp>\u003Cp>The notices included employees and student employees, increasing the relevance of employment-themed scams. A match alone, however, does not prove that a person was a Tulane employee, student, or member of any other specific group.\u003C\u002Fp>\u003Ch2>Identity and financial risks\u003C\u002Fh2>\u003Cp>Names combined with Social Security numbers can enable identity theft, fraudulent tax filings, and new-account fraud. Affected people should consider monitoring their credit reports and placing a credit freeze or fraud alert where appropriate.\u003C\u002Fp>\u003Cp>Bank activity and payroll deposit instructions should be reviewed for unexpected changes. If an unfamiliar account change appears, contact the bank and the university payroll office through known official channels.\u003C\u002Fp>\u003Ch2>Oracle- and payroll-themed scams\u003C\u002Fh2>\u003Cp>Because the incident involved an Oracle-based human-resources system, attackers may create messages involving software updates, employee accounts, payroll migration, or security verification. The use of real technical details does not make a message trustworthy.\u003C\u002Fp>\u003Cp>Instead of following an unexpected link, go directly to Tulane’s official IT, human-resources, or payroll page. Requests for passwords, one-time codes, banking information, or payment should be verified through an independent second channel.\u003C\u002Fp>\u003Ch2>How should a result be interpreted?\u003C\u002Fh2>\u003Cp>A positive match means the queried address appears within records associated with this incident; it does not prove that every listed field belongs to that individual or establish a specific university relationship. A personal notice is the primary source for individual scope.\u003C\u002Fp>\u003Cp>A negative result does not prove that a person was unaffected; it only means no match was found in the currently available data. Anyone who received a direct notice from Tulane should follow the university’s protective guidance regardless of the result.\u003C\u002Fp>","","Tulane University Data Breach (80.9 Thousand People Affected)","Tulane University breach affected 80,867 people, exposing names, Social Security numbers, direct-deposit details, and banking information.","https:\u002F\u002Ftulane.edu\u002Fthemes\u002Fcustom\u002Ftulane_tailwindcss\u002Flogo.svg",false,{"name":34,"sector":35,"country":36,"website":10,"websiteArchiveUrl":28,"websiteStatus":37,"websiteCheckedAt":12},"Tulane University","Education","United States","active"]