• News/
  • https://www.theregister.com/2025/12/02/clop_university_of_pennsylvania/

University of Pennsylvania joins list of victims from Clop's Oracle EBS raid

The Register
·
Carly Page
·
Published Dec 2, 2025
·
Updated

The University of Pennsylvania has become the latest victim of Clop's smash-and-grab spree against Oracle's E-Business Suite (EBS) customers, with the Ivy League school now warning more than a thousand individuals that their personal data was siphoned from its systems. In a data breach notification letter filed with Maine's attorney general, Penn says attackers exploited a zero-day in Oracle's EBS – the same flaw Clop boasted about abusing to raid hundreds of organizations worldwide – and made off with data stored inside the university's instance of the platform, which it uses to process "supplier payments, reimbursements, general ledger entries, and to conduct other University business." Penn launched an investigation, patched its systems after Oracle issued fixes, and alerted federal law enforcement. The university says it discovered on November 11 that personal data had been stolen from its systems. The notification, filed on December 1, confirms that 1,488 Maine residents were among those caught up in the haul, though it offers no total victim count. The description of the compromised data is conspicuously redacted in the template sent to regulators, leaving it unclear what categories of personal information were taken. The Register asked Penn for more details, but did not receive a response by the time of publication. Penn's disclosure lands just a week after Dartmouth College confirmed that it too fell prey to the same Oracle EBS zero-day. In its own filing, the fellow ...

Read full article

Affected Software

1 affected component
Oracle E-Business Suite

Frequently Asked Questions

1

What organization was recently attacked by the Clop ransomware group?

The University of Pennsylvania was recently targeted by the Clop ransomware group.

2

What software vulnerability did Clop exploit in their attack?

Clop exploited vulnerabilities in the Oracle E-Business Suite software to carry out their attack.

3

How many individuals were affected by the Clop ransomware attack on the University of Pennsylvania?

More than a thousand individuals were warned about the breach resulting from the attack.

4

What is the primary focus of Clop's recent cyber attacks?

Clop's recent cyber attacks are primarily focused on Oracle E-Business Suite customers.

5

What steps should affected individuals take following the Clop ransomware attack?

Affected individuals should monitor their accounts for suspicious activity and consider enhancing their cyber hygiene practices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203