[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fx7fn0l4lgugr":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":4,"isSpamList":34,"isMalware":34,"company":35},"6a714a5b931ca7cb76fccbe1","UniversityOfPhoenix2025","University of Phoenix 2025 Data Breach","university-of-phoenix-2025","phoenix.edu","2025-08-13T00:00:00.000Z","2026-08-04T02:11:38.862Z","University of Phoenix SEC filing, Washington Attorney General filing, and Texas Attorney General record","https:\u002F\u002Fwww.sec.gov\u002FArchives\u002Fedgar\u002Fdata\u002F1600222\u002F000095014225003098\u002Feh250711375_8k.htm",[14,16,17],"https:\u002F\u002Fagportal-s3bucket.s3.amazonaws.com\u002Fdatabreach\u002FBreachA35944.pdf","https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage",3489274,"known",null,"people","Critical",[24,25,26,27,28],"Names","Dates of birth","Social security numbers","Bank account numbers","Bank routing numbers","\u003Cp>\u003Cstrong>The 2025 University of Phoenix data breach\u003C\u002Fstrong> involved personal information being copied after an unauthorized party exploited a previously unknown vulnerability in the university's Oracle E-Business Suite software. The Texas Attorney General record reports 3,489,274 affected people nationwide.\u003C\u002Fp>\u003Cp>University of Phoenix is a U.S. higher-education institution that primarily offers online undergraduate and graduate programs for working adults. The incident was disclosed as affecting the university's Oracle EBS enterprise-resource-planning environment.\u003C\u002Fp>\u003Ch2>How did the University of Phoenix data breach happen?\u003C\u002Fh2>\u003Cp>An unauthorized third party exploited a then-unknown Oracle EBS vulnerability and exfiltrated data from the university's environment between August 13 and August 22, 2025. The university learned of the potential incident on November 21 and confirmed the unauthorized data transfer on November 24.\u003C\u002Fp>\u003Cp>The company's SEC filing says the incident did not disrupt business operations or student programming. That does not mean personal information was unaffected; the event concerned data held in the enterprise software environment.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>According to the official notices, affected information may include names, dates of birth, Social Security numbers, bank account numbers, and bank routing numbers.\u003C\u002Fp>\u003Cp>Not every listed field necessarily applied to every person. The Washington regulator notice says the bank account and routing numbers were present without information that provided a means of access.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The Texas Attorney General reports 3,489,274 affected individuals in total, including 304,393 Texas residents. The Washington filing separately reports 64,796 affected residents of that state.\u003C\u002Fp>\u003Ch2>What risks can this information create?\u003C\u002Fh2>\u003Cp>A Social Security number and date of birth can support identity theft, fraudulent account applications, or attempts targeting a person's credit history. Bank account details can also make a scam message appear to refer to a genuine financial transaction.\u003C\u002Fp>\u003Cp>For an unexpected message claiming to come from the university, a student-loan provider, or a bank, use the organization's official contact channel instead of following a supplied link. Accurate education or account details do not prove the sender is authorized.\u003C\u002Fp>\u003Ch2>How did University of Phoenix respond?\u003C\u002Fh2>\u003Cp>The university investigated with outside cybersecurity specialists, installed Oracle's released software patches, and notified law enforcement. It offered affected people complimentary identity-protection services through IDX.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients can enroll in the offered protection service before the stated deadline and regularly review credit reports and bank accounts for unfamiliar activity. A fraud alert or credit freeze may also be appropriate depending on individual circumstances.\u003C\u002Fp>\u003Cp>If an unfamiliar transaction appears, contact the relevant bank or credit provider directly. Do not share a password, one-time code, or payment information in response to an unexpected call or message.\u003C\u002Fp>","","University of Phoenix Data Breach (3.5 Million People Affected)","The University of Phoenix data breach affected 3,489,274 people and may have exposed identity and bank account information.","\u002Fuploads\u002Flogo\u002Funiversity-of-phoenix.png",false,{"name":36,"sector":37,"country":38,"website":39,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":20},"University of Phoenix","Education","United States","https:\u002F\u002Fwww.phoenix.edu\u002F"]