Phoenix Education Partners, Inc.

Dec 2025 · Graded Verified · Public Sector and Education · Government record

Incident summary

Phoenix Education Partners, Inc.Dec 2025
breach at The University of Phoenix, Inc.
$5.1M
Spent responding & recovering
Direct expense
The break-in came through Oracle's E-Business Suite, the back-office platform Phoenix shared with a hundred other victims, where a single zero-day in the reporting engine handed the Cl0p group the run of the place. Over ten days in August the attackers left with names, Social Security numbers, and bank routing numbers for roughly 3.5 million students, alumni, and staff; the university noticed in November. A shared enterprise platform is not infrastructure; it is one lock that opens a hundred doors.
Verified: the linked document states this figure.
Public Sector and Education
SEC 8-K, Item 8.01
Initial attack type software vulnerability confirmed · Impact data theft confirmed + data extortion · Actor Cl0p
Quantified 224 days after disclosure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
2026-07-14$5.1MVVerifiedSEC 10-Q ↗

About this record

This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete On the Government Record ledger ← Back to the index