HomeSecurityUniversity of Pennsylvania: New data breach via Oracle EBS

University of Pennsylvania: New data breach via Oracle EBS

The University of Pennsylvania (Penn) is once again in the spotlight after a new data breach was revealed in August. Attackers managed to steal files containing personal information by exploiting a previously unknown vulnerability in Oracle E-Business Suite (EBS).

University of Pennsylvania Oracle EBS

The historic university, founded in 1740, has more than 29,000 students and nearly 6,000 faculty members, and manages a budget of billions of dollars. Yet its digital armor looks set to be sorely tested in 2025.

Second incident in a few months

The August incident wasn't the only one to rock Penn this year. In October, it was revealed that hackers had infiltrated internal systems related to development and alumni relations, removing data on about 1.2 million students, alumni and donors. The new incident adds to concerns that the Ivy League institutions are now a regular target for organized cybercrime groups.

See also: Coupang: Data breach affects 34 million customers

Meanwhile, in recent weeks, Harvard and Princeton revealed they had been victims of vishing attacks , which gave attackers access to systems containing critical personal data . The increasing frequency of such incidents shows that threat actors are exploiting security gaps at universities, a sector that often combines old systems with vast amounts of sensitive information.

The zero-day in Oracle EBS and data theft

According to the notice filed with the Maine Attorney General's Office, the attackers exploited a previously unknown zero-day vulnerability in Oracle EBS, gaining access to documents containing personally identifiable information. Officially, the university reports 1,488 victims, but the true impact may be much higher.

University of Pennsylvania: New data breach via Oracle EBS

The University of Pennsylvania reported that it discovered the unauthorized data extraction on November 11. Although the notification letters obscure the type of information, the university confirmed that at least names and basic personal identifiers were among the records removed.

A spokesperson for the institution said Penn was one of nearly 100 institutions affected by the same massive Oracle exploit campaign. According to the university, patches have already been applied Oracle and there is no indication that data has been publicly leaked or used for fraud.

See also: Handala targets Israeli tech and aerospace sector

Clop behind the new series of attacks?

Although the University of Pennsylvania is avoiding naming the perpetrators, everything indicates that the attack is related to the well-known ransomware gang Clop. The group has been exploiting the zero-day CVE-2025-61882 since early August, systematically targeting organizations using Oracle EBS.

Clop has already posted stolen data from Harvard, the Washington Post, GlobalLogic, Logitech , and Envoy Air on dark web sites, offering it via Torrent. The fact that Penn has not yet been added to the list of leaks raises two possible scenarios: either a ransom negotiation is underway or the university has already paid a price to prevent the release.

The Bigger Picture: An Unstable Security Ecosystem

Clop’s attacks are not an isolated phenomenon. Over the past five years, the group has been involved in massive data theft operations, from the Accellion FTA and GoAnywhere MFT breaches to the historic MOVEit breach that affected more than 2,700 organizations worldwide.

The threat is considered so serious that the US State Department is now offering a $10 million reward for information linking Clop's actions to a foreign government.

See also: French Football Federation reveals data breach

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

University of Pennsylvania: New data breach via Oracle EBS

What does this mean for universities?

Educational institutions, especially those with large financial ecosystems and extensive alumni networks, manage vast volumes of personal data – from financial information to research records. Penn is a prime example of how vulnerable these systems can be when combined with legacy applications, limited security resources and complex organizational structures.

The need to invest in modern security solutions, constant monitoring, and timely patching is more urgent than ever. 2025 is shaping up to be a year that reshapes how universities approach cyberspace — not as a convenience tool, but as a critical battlefield.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS