Phoenix Education Partners reports Oracle-linked cybersecurity data breach
Phoenix Education Partners, Inc., parent of The University of Phoenix, reports a cybersecurity incident involving its Oracle E‑Business Suite platform.
Rhea-AI Filing Summary
Phoenix Education Partners, Inc., parent of The University of Phoenix, reports a cybersecurity incident involving its Oracle E‑Business Suite platform. An unauthorized third party exploited a previously unknown Oracle vulnerability and, in August 2025, copied certain data from the Company’s Oracle EBS environment. The breach appears to have exposed personal information such as names, contact details, dates of birth, Social Security numbers, and bank account and routing numbers for numerous individuals.
The incident was detected on November 21, 2025, after which the Company engaged third‑party cybersecurity firms, applied Oracle patches released in October 2025, and began notifying affected parties and regulators. The Company states that operations and student programming were not impacted and, as of this report, it believes the incident will not have a material adverse effect on its business operations or student programming. It expects to incur related expenses but notes that it maintains cybersecurity insurance that may cover incident response, remediation, regulatory, business interruption and legal costs, subject to deductibles, exclusions and limits.
Positive
- None.
Negative
- Material cybersecurity incident involving sensitive personal data, including Social Security and bank account details for numerous individuals, creating elevated legal, regulatory, and reputational risk despite unchanged operations.
Insights
PXED discloses a significant data breach with insured but uncertain financial and legal fallout.
Phoenix Education Partners reports that a previously unknown vulnerability in Oracle E‑Business Suite was exploited in August 2025 to copy data from its environment. Exposed information includes highly sensitive personal identifiers (Social Security and bank account numbers), which raises meaningful legal, compliance, and reputational risk, even though core business operations and student programming were not disrupted.
The Company detected the incident on November 21, 2025, engaged leading third‑party cybersecurity firms, and installed Oracle patches released in October 2025. Management currently believes the incident will not have a material adverse effect on business operations or student programming, but acknowledges it will incur incident‑related expenses and is still reviewing impacted data and regulatory notification obligations.
The Company maintains a comprehensive cybersecurity insurance policy that covers incident response, remediation, regulatory action, business interruption, and legal proceedings, subject to deductibles, exclusions, and limits. Actual financial impact will depend on the final scope of compromised data, potential regulatory inquiries or litigation, and the extent of recoveries under the policy as clarified in future SEC filings.
8-K Event Classification
FAQ
What cybersecurity incident did Phoenix Education Partners (PXED) disclose?
What types of personal data were exposed in PXEDs cybersecurity incident?
Did the cybersecurity breach affect Phoenix Education Partners operations or student programming?
When did Phoenix Education Partners discover the Oracle EBS breach and how did it respond?
Does Phoenix Education Partners have cyber insurance for this incident?
AI-generated analysis. How Rhea-AI works. Not financial advice.