INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Clop Ransomware Group Linked to 3.5m University of Phoenix Breach
| 2025-12-23 16:00 HIGH LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
A data breach affecting nearly 3.5 million individuals, including current and former students, staff, faculty, and suppliers of the University of Phoenix, was disclosed in early December after attackers gained unauthorized access to its systems during the summer between August 13 and November 21, 2025. The breach is linked to the Clop ransomware group, which exploited a zero-day vulnerability in Oracle E-Business Suite (EBS) financial application tracked as CVE-2025-61882. Nearly 3.489 million individuals were affected, including approximately 9131 Maine residents, with compromised data including personal and financial information that was accessed without authorization but not obtained through means of access to bank details. The attack is believed to be part of a broader campaign targeting over 100 organizations across multiple sectors, making it the fourth-largest ransomware attack in the world this year based on records affected.
Technical Mitigations AI-generated
• Patch Oracle E-Business Suite (EBS) to address CVE-2025-61882 zero-day vulnerability.
• Monitor for suspicious activity related to FIN11 threat group and Clop ransomware gang.
• Implement dark web monitoring as part of identity protection services offered by the University of Phoenix.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-61882CVE-2025-61882
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
educationeducation
Incident Timeline
2025/12/23
The University of Phoenix breach, linked to the Clop ransomware gang's data leak site, occurred between August 13 and November 21, 2025.
Click on any entity below to view its context and source!
financial
$1 $ reimbursement policy
These include 12 months of credit monitoring, identity theft recovery assistance, dark web monitoring and a $1m fraud reimbursement policy.
victims
100 organizations
The campaign, which surfaced publicly in early October, has targeted more than 100 organizations across multiple sectors.
Tactical Metrics
Metrics
financial
1,000,000
$ Reimbursement Policy
Click for context!
These include 12 months of credit monitoring, identity theft recovery assistance, dark web monitoring and a $1m fraud reimbursement policy.
Metrics
victims
100
Organizations
The campaign, which surfaced publicly in early October, has targeted more than 100 organizations across multiple sectors.
Intelligence Sources
Infosecurity-Magazine
2025-12-23
Clop Ransomware Group Linked to 3.5m University of Phoenix Breach
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:36
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
organisation
Identified Entity
Phoenix Education Partners
entity
4x
timeline
Temporal Reference
2025
date
4x
tactic
Cyber Operation Type
Ransomware
tactic
2x
general metric
Individuals
3,500,000
individuals
Contextual Telemetry
Context Block
7 METRICS
source region
Origin Country
United States
country
industry
Targeted Sector
Education
sector
target region
Target Country
United States
country
vulnerability
Exploited CVE
CVE-2025-61882
cve
campaign
Campaign
Campaign
The
operation
financial
$ Reimbursement Policy
1,000,000
$ reimbursement policy
victims
Organizations
100
organizations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.