Full Report
The University of Pennsylvania (Penn) has confirmed a new data breach after attackers stole documents containing personal information from its Oracle E-Business Suite servers in August. [...]
Analysis Summary
# Incident Report: University of Pennsylvania Oracle EBS Data Breach
## Executive Summary
In August 2025, the University of Pennsylvania (Penn) suffered a data breach where attackers exploited a zero-day vulnerability in their Oracle E-Business Suite (EBS) servers to steal documents containing personal information. The incident impacted the personal data of at least 1,488 individuals, confirmed by a Maine Attorney General filing on November 11, 2025. Penn initiated an internal review upon discovery and notified affected parties, though the exact number of affected persons and attribution remain pending disclosure.
## Incident Details
- **Discovery Date:** November 11, 2025 (Date when Penn determined data was obtained, based on notification filing date).
- **Incident Date:** August 2025 (When data theft occurred).
- **Affected Organization:** University of Pennsylvania (Penn).
- **Sector:** Education (Ivy League Research University).
- **Geography:** United States (Location of the University).
## Timeline of Events
### Initial Access
- **Date/Time:** Early August 2025 (Implied start of the broader Clop campaign).
- **Vector:** Exploitation of a previously unknown zero-day security vulnerability in the Oracle E-Business Suite (EBS) financial application.
- **Details:** This exploit is linked to a wider extortion campaign widely attributed to the Clop ransomware gang.
### Lateral Movement
- **Details:** The article does not specify internal lateral movement, suggesting the attack focused on data exfiltration directly from the compromised Oracle EBS servers.
### Data Exfiltration/Impact
- **Details:** Attackers stole files containing personal information, including names or other personal identifiers, belonging to impacted individuals from the Oracle EBS servers.
### Detection & Response
- **Details:** Penn conducted its own investigation, during which the unauthorized data access was discovered. A detailed review was initiated to identify affected individuals, concluding on November 11, 2025, with notification letters filed with the Maine OAG.
## Attack Methodology
- **Initial Access:** Exploitation of a zero-day flaw in Oracle E-Business Suite (CVE-2025-61882, based on context regarding the Clop campaign).
- **Persistence:** Not specified in the context.
- **Privilege Escalation:** Not specified in the context, likely leveraging the zero-day to gain sufficient access to the application's data stores.
- **Defense Evasion:** Exploiting a zero-day vulnerability suggests a high degree of evasion against existing security controls.
- **Credential Access:** Not specified in the context.
- **Discovery:** Not specified in the context.
- **Lateral Movement:** Not specified in the context.
- **Collection:** Gathering files containing personal information from the Oracle EBS environment.
- **Exfiltration:** Theft of sensitive files containing personal data.
- **Impact:** Unauthorized data access and exfiltration.
## Impact Assessment
- **Financial:** Not specified, although the university has a large operating budget ($4.7B) and endowment ($24.8B).
- **Data Breach:** Personal information, including names or other personal identifiers, belonging to at least 1,488 individuals. The exact total number affected remains undisclosed by Penn.
- **Operational:** No reported operational disruption mentioned in the summary.
- **Reputational:** Negative publicity related to the breach, occurring shortly after confirmation of another major incident in October 2025.
## Indicators of Compromise
- **Network Indicators:** None provided (URLs/IPs defanged).
- **File Indicators:** None provided.
- **Behavioral Indicators:** Exploitation of Oracle EBS zero-day vulnerability (CVE-2025-61882).
## Response Actions
- **Containment Measures:** Not explicitly detailed, but unauthorized access was eventually confirmed via internal investigation.
- **Eradication Steps:** Not specified.
- **Recovery Actions:** Not specified, other than initiating notification procedures.
- **Other Actions:** Notified the Maine Attorney General’s office on or around November 2, 2025, confirming compromise on November 11, 2025.
## Lessons Learned
- The use of known, highly effective attack chains (like Clop's Oracle EBS zero-day exploitation) against critical financial systems highlights vulnerabilities in third-party application security postures.
- Penn experienced a second major breach in late 2025, indicating potential gaps in security monitoring or remediation between incidents.
## Recommendations
- Expedite patching or isolation of all Oracle E-Business Suite infrastructure immediately, especially if the implicated zero-day has since been patched.
- Conduct a comprehensive security review of all high-value institutional databases (like financial and HR systems) to ensure robust perimeter and access controls separate from general network environments.
- Review incident response procedures focusing on faster detection and accurate scoping following major application compromises.