In August 2025, the University of Pennsylvania discovered a data breach stemming from a previously unknown security vulnerability in Oracle E-Business Suite, a third-party vendor used for various operational tasks. The breach was part of a larger Clop ransomware campaign targeting Oracle EBS customers. The University disclosed the incident in November 2025 and sent notification letters to affected individuals in December 2025.
The breach involved Personally Identifiable Information (PII), including names, Social Security numbers (SSNs), dates of birth, contact information, and financial account details such as bank account and routing numbers. According to university findings, credit card numbers were not compromised. While 1,488 affected residents in Maine were confirmed through the Maine Attorney General filing, the total number of affected individuals remains unconfirmed, with initial estimates suggesting up to 1.2 million entries across students, alumni, and donors.
The University of Pennsylvania states there is no evidence that this information has been publicly disclosed or misused. The University is offering 24 months of complimentary Experian IdentityWorks services to affected individuals.