HomeSecurityDartmouth College: Data Breach via Oracle EBS

Dartmouth College: Data Breach via Oracle EBS

Dartmouth College has confirmed that it has suffered a major data breach, following the release of files stolen from Oracle E-Business Suite (EBS) and posted on a dark web leak site run by the infamous Clop. The historic university, founded in 1769 and known for its long-standing research work, has a $9 billion endowment and over 40 academic departments, making the cyberattack all the more concerning given the scale and strategic value of the data it manages.

Dartmouth College Data Breach

Zero-Day Exploit for Mass Theft of Sensitive Files

According to the official announcement filed with the Maine Attorney General's office, hackers exploited a previously unknown vulnerability zero-day in Oracle EBS to obtain data on at least 1,494 people. The true extent, however, is believed to be much greater, as Dartmouth has not yet filed a full report with New Hampshire, the state in which it is based.

See also: SitusAMC: Data breach affects customers

Cybercriminals allegedly accessed the servers between August 9 and 12, 2025 , during which time they managed to copy files containing names, social security numbers , and financial account information .

In letters to victims, the university says that a full analysis of the files was only completed on October 30, 2025, suggesting a complex and extensive investigation to identify all affected data.

Silence from Dartmouth and Escalation of the Clop Campaign

So far, the foundation has not provided clear answers on whether the Clop gang demanded a ransom or the overall scope of the breach. However, Clop consistently follows the same pattern: instead of encrypting systems, it steals data and threatens to make it public, pressuring victims to pay.

Dartmouth College: Data Breach via Oracle EBS

The Dartmouth attack is part of a broader international extortion campaign , based on the Oracle EBS vulnerability CVE-2025-61882 . John Hultquist , a principal analyst at Google’s Threat Intelligence Group, estimates that “dozens of organizations” have already been compromised.

See also: Harvard University data breach affects alumni and donors

Big Names on the Victim List: Harvard, Washington Post, Logitech

The same zero-day was used in attacks on other leading organizations, including:

  • Harvard University
  • The Washington Post
  • Logitech
  • GlobalLogic
  • Envoy Air (subsidiary of American Airlines)

All of the stolen data from these organizations has now been leaked publicly and is circulating on torrent networks, escalating the risk of secondary attacks, such as identity theft and financial fraud.

The Clop gang also has a history of massive cyberattacks on file transfer platforms such as Accellion FTA, GoAnywhere MFT, Cleo, and MOVEit Transfer – with the MOVEit attack affecting over 2,770 organizations worldwide. It’s no coincidence that the US State Department is offering a $10 million reward for information linking the gang to a foreign government.

See also: Cox Enterprises: Data breach via Oracle EBS

Dartmouth College: Data Breach via Oracle EBS

Ivy League Universities Under Siege in Cyberspace

The Dartmouth incident is not an isolated incident. In recent weeks, top Ivy League universities – Harvard, Princeton and the University of Pennsylvania – have revealed breaches of their internal systems for developing and managing alumni. In these attacks, hackers stole personal information from students, alumni, donors and faculty, reinforcing the narrative that educational institutions have become one of the most vulnerable and valuable targets.

What This Attack Means for the Education Sector

The Dartmouth College breach highlights a critical truth: Universities with vast volumes of sensitive data often operate with infrastructures that are not designed to address sophisticated cyberthreats. The increasing reliance on commercial software platforms, such as Oracle EBS, creates cascading vulnerabilities, where a single zero-day can compromise dozens of organizations.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The Dartmouth case is likely to act as a catalyst for more aggressive cybersecurity policies and stricter investments in academia – a sector that has been a goldmine of data for the cybercriminal world for years.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS