Your personal information was stored with an institution you trusted. Now it may be in the hands of criminals who had months to use it before anyone even knew they had it.
That is the reality facing nearly 3.5 million people connected to the University of Phoenix after a cyberattack silently compromised the school's financial systems in August 2025. The breach exposed some of the most sensitive data a person can lose: Social Security numbers, bank account details, dates of birth, and contact information. For many victims, the notification letter arrived in December, months after the damage may have already begun.
If you are a current or former student, employee, faculty member, or supplier of the University of Phoenix, this page is written for you. Understanding what happened, what was taken, and what legal options may be available to you in Tennessee is essential. It may be essential to protect your financial future.
Overview of the University of Phoenix Data Breach
What Actually Happened
The University of Phoenix data breach began without warning. Between August 13 and August 22, 2025, an unauthorized third party gained access to the university's Oracle E-Business Suite (EBS) environment, a platform used to manage the university's financial records, administrative data, and operational information.
The attack exploited CVE-2025-61882, a previously unknown zero-day vulnerability in Oracle EBS with a severity score of 9.8 out of 10 on the Common Vulnerability Scoring System. Security researchers and investigators linked the attack to the Clop ransomware group, which used this same vulnerability to breach more than 100 organizations globally, including other U.S. universities such as Harvard and Dartmouth. The University of Phoenix is among the largest known victims of this specific campaign.

According to reporting by SecurityWeek, compromised information includes names, dates of birth, Social Security numbers, and bank account and routing numbers, though the university noted that banking data was obtained without the means to directly access those accounts. That distinction does not eliminate risk. Criminals who hold your Social Security number paired with your banking details have more than enough to open fraudulent new accounts, apply for credit in your name, or sell your profile on the dark web to other bad actors.
Oracle released patches for the vulnerability in October 2025. The University of Phoenix applied those patches after they became available. The problem, as security experts have widely noted, is that the data had already been exfiltrated weeks before the patch existed.
Timeline of Events
- Understanding when things happened matters for anyone considering legal action. Here is the documented sequence:
- August 13 to 22, 2025, Attackers access the university's Oracle EBS environment and exfiltrate data over a 10-day window. The university does not yet know the intrusion has occurred.
- October 2025, Oracle publicly releases patches for CVE-2025-61882 after being alerted to the vulnerability. The university applies these patches after their release.
- November 20, 2025, The Clop ransomware group publicly lists the University of Phoenix on its data leak site, effectively announcing the breach publicly before the university has notified anyone.
- November 21, 2025, The University of Phoenix discovers the breach and engages third-party cybersecurity firms to investigate.
- December 2, 2025, Phoenix Education Partners, Inc., the university's parent company, files an 8-K disclosure with the U.S. Securities and Exchange Commission, publicly acknowledging the incident.
- December 21 to 22, 2025, The university begins notifying affected individuals by written letter and reports the breach to the Attorneys General of California, Maine, Massachusetts, New Hampshire, and Texas.
- March 22, 2026 Deadline for affected individuals to enroll in the free 12-month IDX identity protection services offered by the university.
As Bloomberg Law reported, a class action lawsuit has already been filed against the University of Phoenix and Oracle Corporation, with plaintiffs alleging that both entities failed to implement reasonable security measures to protect sensitive personal information.
Why This Breach Is Particularly Serious
Most data breaches involve one or two types of sensitive information. The University of Phoenix breach exposed a particularly dangerous combination: Social Security numbers paired with dates of birth, contact information, and bank account details. This combination gives bad actors enough information to open fraudulent accounts, file false tax returns, apply for loans in a victim's name, and commit a wide range of financial crimes.
According to data published by the Federal Trade Commission, consumers reported losing more than $12.5 billion to fraud in 2024, a 25% increase over the prior year. More than 1.1 million identity theft reports were filed with the FTC in that same year. When a breach of this scale exposes Social Security numbers and banking information together, the downstream consequences can take years to fully surface and resolve.
Impacts on Tennessee Victims
Nearly 3.5 Million People Were Affected Nationwide
According to official filings with the Maine Attorney General's Office, the University of Phoenix data breach affected exactly 3,489,274 individuals. Those affected include current and former students, employees, faculty members, and suppliers whose personal and financial data were stored in the Oracle EBS platform.
The university began mailing written notification letters in late December 2025. If you are a Tennessee resident who attended the university, worked for it, or did business with it and have not yet received a letter, that does not necessarily mean your information was safe. Notification delays are common in breaches of this scale, and your credit activity may show signs of suspicious use before a formal letter arrives.
According to Top Class Actions, a class action lawsuit has been filed in the U.S. District Court for the Western District of Texas: Pointer et al. v. The University of Phoenix, Inc., et al., Case No. 1:26-cv-00009. The lawsuit alleges that both the University of Phoenix and Oracle Corporation failed to implement and maintain reasonable security measures to protect the personally identifiable information of millions of people.
Identity Theft Concerns Are Real and Long-Lasting
The data stolen in this breach is not the kind of information that becomes less dangerous over time. Social Security numbers are permanent identifiers. Once your number is in criminals' hands, it can be misused repeatedly across multiple fraud schemes, sometimes years after the original breach.
The combination of data elements confirmed as exposed, including names, dates of birth, Social Security numbers, and bank account information, provides enough material for criminals to:
- Open new credit card accounts or personal loans in your name
- File fraudulent tax returns to intercept your refund
- Apply for government benefits or unemployment claims using your identity
- Sell your personal profile on dark web marketplaces to other criminal actors
- Attempt to take over existing financial accounts through social engineering
Under T.C.A. Section 47-18-2107, Tennessee requires breach notification within 45 days of discovery. Delayed notification may strengthen your legal claim. The Federal Trade Commission recommends placing a free credit freeze with Equifax, Experian, and TransUnion immediately to prevent new accounts from being opened in your name without approval.
Seeking Legal Help in Your State
What a Data Breach Claim Can Cover
You do not have to have already experienced financial fraud to have a potential legal claim arising from this breach. Courts have recognized that the exposure of personal data and the real and ongoing risk it creates constitute compensable harm. Potential damages in data breach cases can include:
- Reimbursement for out-of-pocket costs related to the breach, such as paid credit monitoring services or expenses tied to resolving fraudulent accounts
- Compensation for time spent dealing with the aftermath of identity theft
- Damages for emotional distress and loss of privacy
- Statutory damages under applicable state and federal law
These are the categories of harm being raised in the active class action lawsuit against the University of Phoenix and Oracle. You do not have to file a separate individual lawsuit to participate. Class action litigation is designed specifically to allow many affected individuals to pursue accountability collectively.
A data breach attorney can help you understand whether your situation qualifies, what records you should preserve, and how the existing litigation may affect your individual options.
Steps to Take Right Now If You Were Affected
If you received a notification letter from the University of Phoenix or believe your information may have been involved, take these steps now, regardless of whether you plan to pursue legal action:
- Enroll in free IDX services before March 22, 2026, including 12 months of credit monitoring, dark web surveillance, and a $1 million identity fraud reimbursement policy. Enrollment does not waive your right to seek legal compensation.
- Place a free credit freeze with Equifax, Experian, and TransUnion to prevent fraudulent new accounts.
- Monitor bank, credit card, and government benefit statements for suspicious activity.
- Check your free credit reports at AnnualCreditReport.com for unrecognized accounts.
- Save all breach-related correspondence in case you pursue a legal claim.
- Consult your local data breach attorney. Usually, they’ll offer a free case evaluation with no obligation.
Disclaimer: This article is intended for general informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship. Laws vary by jurisdiction, and individual circumstances differ. If you believe your information was exposed in the University of Phoenix data breach, consult a qualified attorney to understand your rights and the options available to you.