Skip to content
Cory Watson Attorneys Logo
  • Cases We Handle
    • Personal Injury
      • Car Accidents
      • Truck Accidents
      • Motorcycle Accidents
      • Pedestrian Accidents
      • Food Poisoning
      • Nursing Home Abuse
      • All Cases We Handle
    • Defective Products
      • NEC Baby Formula Lawsuit
      • Bard Power Port Lawsuit
      • Exactech Connexion GXL Hip Liner Lawsuit
      • Hernia Mesh Lawsuit
      • Portable Blender Lawsuit
      • Pressure Cooker Lawsuit
      • Paragard Lawsuit
    • Drug Injury
      • Ozempic Lawsuit
      • Oxbryta Lawsuit
      • Paragard Lawsuit
    • Class Action
      • Data Breach
      • Ford Recall
    • Environmental Injury
      • AFFF Lawsuit
      • Ethylene Oxide Lawsuit
      • Roundup Lawsuit
      • Camp Lejeune Lawsuit
      • C-8 Dupont Lawsuit
      • East Palestine Train Derailment Lawsuit
  • Office Locations
    • Birmingham
    • Memphis
    • Nashville
  • About Us
    • Our Attorneys
    • Testimonials
    • Case Results
    • Attorney Referrals
    • Cory Watson Cares
  • Blog
    • Firm News
    • Veteran Friendly
  • Contact
  • Search
Call 24/7 – (877) 562-0000
Cory Watson advocates for patients affected by AI Chatbot Harm. SUBMIT A CLAIM
Cory Watson advocates for patients affected by Bard PowerPort®. SUBMIT A CLAIM
Cory Watson advocates for patients affected by a Data Breach. SUBMIT A CLAIM
Cory Watson advocates for patients affected by Social Media Addiction. SUBMIT A CLAIM

University of Phoenix Data Breach: What Tennessee Victims Must Know

Cory Watson Personal Injury Attorneys  >  Blog  >  University of Phoenix Data Breach: What Tennessee Victims Must Know

August 1, 2026 | By Cory Watson Attorneys
University of Phoenix Data Breach: What Tennessee Victims Must Know

Your personal information was stored with an institution you trusted. Now it may be in the hands of criminals who had months to use it before anyone even knew they had it.

That is the reality facing nearly 3.5 million people connected to the University of Phoenix after a cyberattack silently compromised the school's financial systems in August 2025. The breach exposed some of the most sensitive data a person can lose: Social Security numbers, bank account details, dates of birth, and contact information. For many victims, the notification letter arrived in December, months after the damage may have already begun.

If you are a current or former student, employee, faculty member, or supplier of the University of Phoenix, this page is written for you. Understanding what happened, what was taken, and what legal options may be available to you in Tennessee is essential. It may be essential to protect your financial future.

Overview of the University of Phoenix Data Breach

What Actually Happened

The University of Phoenix data breach began without warning. Between August 13 and August 22, 2025, an unauthorized third party gained access to the university's Oracle E-Business Suite (EBS) environment, a platform used to manage the university's financial records, administrative data, and operational information.

The attack exploited CVE-2025-61882, a previously unknown zero-day vulnerability in Oracle EBS with a severity score of 9.8 out of 10 on the Common Vulnerability Scoring System. Security researchers and investigators linked the attack to the Clop ransomware group, which used this same vulnerability to breach more than 100 organizations globally, including other U.S. universities such as Harvard and Dartmouth. The University of Phoenix is among the largest known victims of this specific campaign.

Illustration representing a university data breach and identity theft, showing personal financial and identification data leaking from a campus silhouette.

According to reporting by SecurityWeek, compromised information includes names, dates of birth, Social Security numbers, and bank account and routing numbers, though the university noted that banking data was obtained without the means to directly access those accounts. That distinction does not eliminate risk. Criminals who hold your Social Security number paired with your banking details have more than enough to open fraudulent new accounts, apply for credit in your name, or sell your profile on the dark web to other bad actors.

Oracle released patches for the vulnerability in October 2025. The University of Phoenix applied those patches after they became available. The problem, as security experts have widely noted, is that the data had already been exfiltrated weeks before the patch existed.

Timeline of Events

  • Understanding when things happened matters for anyone considering legal action. Here is the documented sequence:
  • August 13 to 22, 2025, Attackers access the university's Oracle EBS environment and exfiltrate data over a 10-day window. The university does not yet know the intrusion has occurred.
  • October 2025, Oracle publicly releases patches for CVE-2025-61882 after being alerted to the vulnerability. The university applies these patches after their release.
  • November 20, 2025, The Clop ransomware group publicly lists the University of Phoenix on its data leak site, effectively announcing the breach publicly before the university has notified anyone.
  • November 21, 2025, The University of Phoenix discovers the breach and engages third-party cybersecurity firms to investigate.
  • December 2, 2025, Phoenix Education Partners, Inc., the university's parent company, files an 8-K disclosure with the U.S. Securities and Exchange Commission, publicly acknowledging the incident.
  • December 21 to 22, 2025, The university begins notifying affected individuals by written letter and reports the breach to the Attorneys General of California, Maine, Massachusetts, New Hampshire, and Texas.
  • March 22, 2026  Deadline for affected individuals to enroll in the free 12-month IDX identity protection services offered by the university.

As Bloomberg Law reported, a class action lawsuit has already been filed against the University of Phoenix and Oracle Corporation, with plaintiffs alleging that both entities failed to implement reasonable security measures to protect sensitive personal information.

Why This Breach Is Particularly Serious

Most data breaches involve one or two types of sensitive information. The University of Phoenix breach exposed a particularly dangerous combination: Social Security numbers paired with dates of birth, contact information, and bank account details. This combination gives bad actors enough information to open fraudulent accounts, file false tax returns, apply for loans in a victim's name, and commit a wide range of financial crimes.

According to data published by the Federal Trade Commission, consumers reported losing more than $12.5 billion to fraud in 2024, a 25% increase over the prior year. More than 1.1 million identity theft reports were filed with the FTC in that same year. When a breach of this scale exposes Social Security numbers and banking information together, the downstream consequences can take years to fully surface and resolve.

Impacts on Tennessee Victims

Nearly 3.5 Million People Were Affected Nationwide

According to official filings with the Maine Attorney General's Office, the University of Phoenix data breach affected exactly 3,489,274 individuals. Those affected include current and former students, employees, faculty members, and suppliers whose personal and financial data were stored in the Oracle EBS platform.

The university began mailing written notification letters in late December 2025. If you are a Tennessee resident who attended the university, worked for it, or did business with it and have not yet received a letter, that does not necessarily mean your information was safe. Notification delays are common in breaches of this scale, and your credit activity may show signs of suspicious use before a formal letter arrives.

According to Top Class Actions, a class action lawsuit has been filed in the U.S. District Court for the Western District of Texas: Pointer et al. v. The University of Phoenix, Inc., et al., Case No. 1:26-cv-00009. The lawsuit alleges that both the University of Phoenix and Oracle Corporation failed to implement and maintain reasonable security measures to protect the personally identifiable information of millions of people.

Identity Theft Concerns Are Real and Long-Lasting

The data stolen in this breach is not the kind of information that becomes less dangerous over time. Social Security numbers are permanent identifiers. Once your number is in criminals' hands, it can be misused repeatedly across multiple fraud schemes, sometimes years after the original breach.

The combination of data elements confirmed as exposed, including names, dates of birth, Social Security numbers, and bank account information, provides enough material for criminals to:

  • Open new credit card accounts or personal loans in your name
  • File fraudulent tax returns to intercept your refund
  • Apply for government benefits or unemployment claims using your identity
  • Sell your personal profile on dark web marketplaces to other criminal actors
  • Attempt to take over existing financial accounts through social engineering

Under T.C.A. Section 47-18-2107, Tennessee requires breach notification within 45 days of discovery. Delayed notification may strengthen your legal claim. The Federal Trade Commission recommends placing a free credit freeze with Equifax, Experian, and TransUnion immediately to prevent new accounts from being opened in your name without approval.

Seeking Legal Help in Your State

What a Data Breach Claim Can Cover

You do not have to have already experienced financial fraud to have a potential legal claim arising from this breach. Courts have recognized that the exposure of personal data and the real and ongoing risk it creates constitute compensable harm. Potential damages in data breach cases can include:

  • Reimbursement for out-of-pocket costs related to the breach, such as paid credit monitoring services or expenses tied to resolving fraudulent accounts
  • Compensation for time spent dealing with the aftermath of identity theft
  • Damages for emotional distress and loss of privacy
  • Statutory damages under applicable state and federal law

These are the categories of harm being raised in the active class action lawsuit against the University of Phoenix and Oracle. You do not have to file a separate individual lawsuit to participate. Class action litigation is designed specifically to allow many affected individuals to pursue accountability collectively.

A data breach attorney can help you understand whether your situation qualifies, what records you should preserve, and how the existing litigation may affect your individual options.

Steps to Take Right Now If You Were Affected

If you received a notification letter from the University of Phoenix or believe your information may have been involved, take these steps now, regardless of whether you plan to pursue legal action:

  • Enroll in free IDX services before March 22, 2026, including 12 months of credit monitoring, dark web surveillance, and a $1 million identity fraud reimbursement policy. Enrollment does not waive your right to seek legal compensation.
  • Place a free credit freeze with Equifax, Experian, and TransUnion to prevent fraudulent new accounts.
  • Monitor bank, credit card, and government benefit statements for suspicious activity.
  • Check your free credit reports at AnnualCreditReport.com for unrecognized accounts.
  • Save all breach-related correspondence in case you pursue a legal claim.
  • Consult your local data breach attorney. Usually, they’ll offer a free case evaluation with no obligation.

Disclaimer: This article is intended for general informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship. Laws vary by jurisdiction, and individual circumstances differ. If you believe your information was exposed in the University of Phoenix data breach, consult a qualified attorney to understand your rights and the options available to you.

Contact Our 24/7 Nationwide Lawyers

* Required Fields

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Practice Areas

  • Trussville Motorcycle Accident Lawyer
  • Homewood Motorcycle Accident Lawyer
  • Alabaster Motorcycle Accident
  • Spring Hill Motorcycle Accident Lawyer
  • Mount Juliet Motorcycle Accident Lawyer
  • Gallatin Motorcycle Accident Lawyer
  • Columbia Motorcycle Accident Lawyer
  • Smyrna Motorcycle Accident Lawyer
  • Trussville Truck Accident Lawyer
  • Homewood Truck Accident

Table Of Contents

Contact Cory Watson Attorneys

Talking to an experienced attorney from anywhere in the United States shouldn’t be a hassle.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form

Office Locations

Memphis Office
254 Court Avenue
Suite 511
Memphis, TN 38103
(901) 402-2000
Nashville Office
1033 Demonbreun St.
Suite 300
Nashville, TN 37203
(615) 205-0000
Birmingham Office
2131 Magnolia Ave S.
Birmingham, AL 35205
(205)328-2200
Cory Watson Logo
  • About Us
  • Blog
  • Our Attorneys
  • Testimonials
  • Case Results
  • Contact Us
© 2026 Cory Watson Attorneys. | All Rights Reserved. | Sitemap

Alabama Rules of Professional Conduct require the following disclaimer: Case descriptions, recoveries and testimonials presented here are not an indication of future results. Every case is different and must be evaluated on its own facts and circumstances as they apply to the law. Litigation outcome and valuation depend on many factors including jurisdiction, venue, witnesses, parties, testimony and documentary evidence. Furthermore, no representation is made that the quality of legal services to be performed is greater than the quality of legal services performed by other lawyers. Leila H. Watson, 2131 Magnolia Avenue, Birmingham, Alabama 35205, 205-271-7102, is responsible for the contents of this website.

Cory Watson Attorneys SMS and MMS Messaging program assists with lead follow-ups, documents, and screening cases. Message and data rates may apply. Message Frequency May Vary. For help, reply HELP. To opt out, reply STOP. Carriers are not liable for delayed or undelivered messages. For our privacy policy, See Here.

We use cookies and similar technologies to support this website's essential functions, as well as for analytics, personalization, and marketing purposes.