INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Clop Ransomware Group Linked to 3.5m University of Phoenix Breach

| 2025-12-23 16:00 HIGH LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
A data breach affecting nearly 3.5 million individuals, including current and former students, staff, faculty, and suppliers of the University of Phoenix, was disclosed in early December after attackers gained unauthorized access to its systems during the summer between August 13 and November 21, 2025. The breach is linked to the Clop ransomware group, which exploited a zero-day vulnerability in Oracle E-Business Suite (EBS) financial application tracked as CVE-2025-61882. Nearly 3.489 million individuals were affected, including approximately 9131 Maine residents, with compromised data including personal and financial information that was accessed without authorization but not obtained through means of access to bank details. The attack is believed to be part of a broader campaign targeting over 100 organizations across multiple sectors, making it the fourth-largest ransomware attack in the world this year based on records affected.
Technical Mitigations AI-generated
• Patch Oracle E-Business Suite (EBS) to address CVE-2025-61882 zero-day vulnerability. • Monitor for suspicious activity related to FIN11 threat group and Clop ransomware gang. • Implement dark web monitoring as part of identity protection services offered by the University of Phoenix.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-61882CVE-2025-61882
Target & Sectors
NORTH_AMERICA NORTH_AMERICA educationeducation
Incident Timeline
‎2025/12/23
The University of Phoenix breach, linked to the Clop ransomware gang's data leak site, occurred between August 13 and November 21, 2025.
financial $1 $ reimbursement policy
victims 100 organizations
Tactical Metrics
Metrics
financial
1,000,000
$ Reimbursement Policy
Metrics
victims
100
Organizations
Intelligence Sources
Infosecurity-Magazine 2025-12-23