{"id":50330,"date":"2025-12-02T19:39:06","date_gmt":"2025-12-02T19:39:06","guid":{"rendered":"https:\/\/www.newsbeep.com\/us-pa\/50330\/"},"modified":"2025-12-02T19:39:06","modified_gmt":"2025-12-02T19:39:06","slug":"university-of-pennsylvania-joins-growing-pool-of-oracle-customers-impacted-by-clop-attacks","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us-pa\/50330\/","title":{"rendered":"University of Pennsylvania joins growing pool of Oracle customers impacted by Clop attacks"},"content":{"rendered":"<p>The University of Pennsylvania joined the steadily growing number of victim organizations impacted by the <a href=\"https:\/\/cyberscoop.com\/clop-claims-oracle-customers-data-theft\/\" rel=\"nofollow noopener\" target=\"_blank\">widespread data theft and extortion campaign<\/a> involving a notorious ransomware group\u2019s exploitation of a zero-day vulnerability and other defects in Oracle E-Business Suite earlier this year.\u00a0<\/p>\n<p>The university filed a <a href=\"https:\/\/www.maine.gov\/agviewer\/content\/ag\/985235c7-cb95-4be2-8792-a1252b4f8318\/6de24e56-1806-4f42-853e-6c505ee1427f.html\" rel=\"nofollow noopener\" target=\"_blank\">data breach notification in Maine<\/a> Monday, confirming nearly 1,500 Maine residents were affected by an intrusion into its Oracle EBS environment over a three-day period in early August.\u00a0<\/p>\n<p>The Ivy League school and <a href=\"https:\/\/cyberscoop.com\/oracle-customers-attacks-clop-google-mandiant\/\" rel=\"nofollow noopener\" target=\"_blank\">dozens of other victims<\/a> were not aware of the attack until Oracle acknowledged the critical vulnerability after members of the Clop ransomware group sent <a href=\"https:\/\/cyberscoop.com\/extortion-email-clop-oracle-customers\/\" rel=\"nofollow noopener\" target=\"_blank\">extortion emails<\/a> to alleged victim organizations in late September. Attackers <a href=\"https:\/\/cyberscoop.com\/oracle-zero-day-clop\/\" rel=\"nofollow noopener\" target=\"_blank\">exploited multiple vulnerabilities<\/a> to steal large amounts of data from several Oracle EBS customers in August, according to Mandiant.<\/p>\n<p>The university said it determined some personal information was stolen from its Oracle EBS system on Nov. 11, but did not provide details about how many people were impacted and what type of data was stolen during the attack.\u00a0<\/p>\n<p>\u201cThe University of Pennsylvania was one of nearly 100 already identified organizations simultaneously impacted by the widely exploited Oracle E-Business Suite incident, involving a previously unknown security vulnerability in Oracle\u2019s system,\u201da spokesperson for the university said in a statement.<\/p>\n<p>\u201cPenn has implemented the patches that Oracle issued to resolve the vulnerability,\u201d the spokesperson added. \u201cPenn has found no evidence that any of this information has been or is likely to be publicly disclosed or misused for fraudulent purposes.\u201d<\/p>\n<p>Other Ivy League schools were impacted by the targeted attacks on Oracle EBS customers as well, including Dartmouth College and Harvard University.\u00a0<\/p>\n<p>Dartmouth filed data breach disclosures in <a href=\"https:\/\/oag.ca.gov\/system\/files\/Dartmouth%20-%20California%20Notification.pdf\" rel=\"nofollow noopener\" target=\"_blank\">California<\/a> and <a href=\"https:\/\/www.maine.gov\/agviewer\/content\/ag\/985235c7-cb95-4be2-8792-a1252b4f8318\/ce67c791-f72f-415a-91fa-b7ba563ca747.html\" rel=\"nofollow noopener\" target=\"_blank\">Maine<\/a> last month confirming that its Oracle EBS environment was also compromised over a few days in August. Personal data exposed by the breach included names, Social Security numbers and financial account information, according to Dartmouth.\u00a0<\/p>\n<p>Harvard University said it was investigating a data breach involving its Oracle EBS system in mid-October, noting at the time that a limited number of people in a small administrative unit were impacted. Harvard said it found no evidence of compromise to other systems.\u00a0<\/p>\n<p>The pool of victim organizations impacted by the mass exploitation of vulnerabilities in Oracle EBS underscores the risk posed by interconnected and widely used systems.<\/p>\n<p>Cox Enterprises last month said personal data on almost 10,000 people was exposed by an attack on its Oracle EBS environment, which it discovered in late September. The attack occurred during the same period as other victim organizations in August, the media and automotive company said in a <a href=\"https:\/\/oag.ca.gov\/system\/files\/2025-11-20%20-%20Individual%20Notification%20Letter%20Template%20-%20Cox.pdf\" rel=\"nofollow noopener\" target=\"_blank\">data breach notification filed in California<\/a>.\u00a0<\/p>\n<p>Logitech said it, too, was impacted by the widespread attacks on Oracle EBS customers. \u201cThe data likely included limited information about employees and consumers and data relating to customers and suppliers. Logitech does not believe any sensitive personal information, such as national ID numbers or credit card information, was housed in the impacted IT system,\u201d the computer peripherals and software vendor said in a <a href=\"https:\/\/www.sec.gov\/Archives\/edgar\/data\/1032975\/000103297525000085\/logi-20251114.htm\" rel=\"nofollow noopener\" target=\"_blank\">Nov. 20 regulatory filing<\/a>.<\/p>\n<p>Other previously confirmed victims include <a href=\"https:\/\/cyberscoop.com\/washington-post-oracle-clop-attacks\/\" rel=\"nofollow noopener\" target=\"_blank\">The Washington Post<\/a>, Envoy Air and <a href=\"https:\/\/cyberscoop.com\/globallogic-oracle-clop-attacks\/\" rel=\"nofollow noopener\" target=\"_blank\">GlobalLogic<\/a>.\u00a0<\/p>\n<p>Clop specializes in exploiting vulnerabilities in file-transfer services and has successfully intruded multiple technology vendors\u2019 systems to steal massive amounts of data for extortion efforts. These attacks typically flow downstream, ensnaring organizations and people multiple layers removed from the initial targeted victims.<\/p>\n<p>Clop infiltrated MOVEit environments in 2023, ultimately exposing data from more than 2,300 organizations, making it the largest and most significant cyberattack that year.<\/p>\n<p>\t\t\t\t\t<img decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/www.newsbeep.com\/us-pa\/wp-content\/uploads\/2025\/12\/MattKapko.jpg\" alt=\"Matt Kapko\"\/><\/p>\n<p>\n\t\t\tWritten by Matt Kapko<br \/>\n\t\t\tMatt Kapko is a reporter at CyberScoop. His beat includes cybercrime, ransomware, software defects and vulnerability (mis)management. The lifelong Californian started his journalism career in 2001 with previous stops at Cybersecurity Dive, CIO, SDxCentral and RCR Wireless News. Matt has a degree in journalism and history from Humboldt State University.\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"The University of Pennsylvania joined the steadily growing number of victim organizations impacted by the widespread data theft&hellip;\n","protected":false},"author":2,"featured_media":50331,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[4172,28858,28859,22267,28860,28861,28862,28863,28864,28865,28866,28,30,29,28867,4347,28868,28869,28870,28871,28872],"class_list":["post-50330","post","type-post","status-publish","format-standard","has-post-thumbnail","category-pennsylvania","tag-california","tag-clop","tag-cox-enterprises","tag-cybercrime","tag-dartmouth-college","tag-data-breaches","tag-harvard","tag-harvard-university","tag-logitech","tag-moveit-transfer","tag-oracle","tag-pennsylvania","tag-pennsylvania-headlines","tag-pennsylvania-news","tag-ransomware","tag-university-of-pennsylvania","tag-vulnerabilities","tag-vulnerability","tag-vulnerability-disclosure","tag-zero-day","tag-zero-day-exploit"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/posts\/50330","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/comments?post=50330"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/posts\/50330\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/media\/50331"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/media?parent=50330"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/categories?post=50330"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/tags?post=50330"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}