The University of Pennsylvania has become the latest victim of Clop's smash-and-grab spree against Oracle's E-Business Suite (EBS) customers, with the Ivy League school now warning more than a thousand individuals that their personal data was siphoned from its systems. In a data breach notification letter filed with Maine's attorney general, Penn says attackers exploited a zero-day in Oracle's EBS – the same flaw Clop boasted about abusing to raid hundreds of organizations worldwide – and made off with data stored inside the university's instance of the platform, which it uses to process "supplier payments, reimbursements, general ledger entries, and to conduct other University business." Penn launched an investigation, patched its systems after Oracle issued fixes, and alerted federal law enforcement. The university says it discovered on November 11 that personal data had been stolen from its systems. The notification, filed on December 1, confirms that 1,488 Maine residents were among those caught up in the haul, though it offers no total victim count. The description of the compromised data is conspicuously redacted in the template sent to regulators, leaving it unclear what categories of personal information were taken. The Register asked Penn for more details, but did not receive a response by the time of publication. Penn's disclosure lands just a week after Dartmouth College confirmed that it too fell prey to the same Oracle EBS zero-day. In its own filing, the fellow ...
University of Pennsylvania joins list of victims from Clop's Oracle EBS raid
The Register
·Carly Page
·Published Dec 2, 2025
·Updated
Affected Software
1 affected component
Oracle E-Business Suite
Frequently Asked Questions
1
What organization was recently attacked by the Clop ransomware group?
The University of Pennsylvania was recently targeted by the Clop ransomware group.
2
What software vulnerability did Clop exploit in their attack?
Clop exploited vulnerabilities in the Oracle E-Business Suite software to carry out their attack.
3
How many individuals were affected by the Clop ransomware attack on the University of Pennsylvania?
More than a thousand individuals were warned about the breach resulting from the attack.
4
What is the primary focus of Clop's recent cyber attacks?
Clop's recent cyber attacks are primarily focused on Oracle E-Business Suite customers.
5
What steps should affected individuals take following the Clop ransomware attack?
Affected individuals should monitor their accounts for suspicious activity and consider enhancing their cyber hygiene practices.