Skip to content
Back to Blog
low severity December 21, 2025 · 4 min read

University of Phoenix, Inc. Data Breach Notice (Oregon Attorney General)

If you received a notice from University of Phoenix, Inc., here’s what the filing says was exposed, and what to do about it.

University of Phoenix, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on December 21, 2025. The filing puts the incident itself on August 13, 2025.

University of Phoenix, Inc. Data Breach Notice (Oregon Attorney General)

The University of Phoenix notified Oregon residents on December 21, 2025, that a data breach exposing the personal information of 3,489,274 people occurred on August 13, 2025. That 130-day gap between the incident and the filing is the longest interval in any recent higher-education breach notification and is now the central fact Oregon residents must weigh.

130 Days Passed Before Oregon Was Told

The filing lists the incident date as August 13, 2025, and the submission date as December 21, 2025. The 130 days that elapsed represent more than four months. Notification timelines vary by the scope of investigation required, but the length of this interval stands out and will shape how current and former students view the university’s handling of the matter.

What “Personal Information” Actually Means Here

The record names only one category: personal information. In Oregon breach filings this term almost always includes name plus one or more of the following: Social Security number, driver’s license number, financial account data, or date of birth. Because the filing does not break the categories down further, you cannot assume every record contained every field. Your own notification letter is the only document that can tell you exactly which pieces of your information were included.

No passwords, no login credentials, and no biometric data appear in the disclosed categories. That absence is meaningful. The exposure centers on persistent identifiers that cannot be reissued the way a compromised password or credit card can.

Why This Exposure Retains Value Long After the News Cycle Ends

A Social Security number paired with a name and date of birth remains valuable to identity thieves for years. These pieces of information do not expire. They allow new-account fraud, tax-refund theft, and medical-identity schemes that can surface months or years later. The scale — more than 3.4 million records — increases the chance that information from this incident will appear on dark-web marketplaces or in bulk datasets used for automated fraud attempts.

Because the university serves adult learners, many of whom have used federal student aid, the overlap between exposed personal information and existing federal records creates a wider surface for synthetic-identity attacks and unemployment-benefit fraud.

How to Determine Whether You Are One of the 3,489,274 Affected

The university is required to notify affected individuals directly, usually by mail to the last known address on file. If you have not received a letter, it is likely your records were not part of this incident. However, anyone who has moved since August 13, 2025, should contact the University of Phoenix privacy office directly to confirm whether their information was included. Absence of a letter is not absolute proof of safety when addresses change.

What Remains Permanent and What You Can Still Control

Your name, date of birth, and Social Security number cannot be changed. Once they are in the hands of unknown parties, the risk cannot be eliminated, only managed. Credit monitoring and identity-theft protection services can alert you to suspicious activity, but they do not prevent the initial misuse. The most practical ongoing defense is vigilance: reviewing credit reports, tax transcripts, and Explanation of Benefits statements for accounts you did not open.

The fact that no credentials were exposed means you do not need to change your University of Phoenix password as a direct result of this incident. That single reassurance frees you to focus effort on the non-revocable data instead of chasing actions that provide no protection here.

The Gap Between What Happened and What You Can Still Do

With more than three million records involved, this breach will almost certainly lead to follow-on fraud attempts aimed at current and former students. The university cannot undo the exposure. You can still limit the damage by placing freezes with the three major credit bureaus, setting up alerts on your credit files, and monitoring IRS and state tax accounts for unexpected filings.

Placing a credit freeze remains the single most effective step available. It stops new accounts from being opened in your name without your explicit permission. Unlike fraud alerts, a freeze does not rely on the creditor checking an alert; it simply blocks the attempt.

Reviewing your annual credit reports from Equifax, Experian, and TransUnion costs nothing and should be done at least twice in the next twelve months. Look for accounts you do not recognize. Also request a transcript of your federal tax filings through the IRS website; fraudulent returns are a common early use of stolen Social Security numbers.

Keep records of every communication with the university about this incident. Should fraudulent activity appear later, documentation that your data was exposed in this specific breach can help resolve disputes with creditors and government agencies more quickly.

The 130-day delay does not change what you must do now, but it does underscore that the responsibility for protecting the long-term consequences has shifted from the institution to you. The letter in your mailbox, or its absence, remains the only definitive answer to whether you were among the 3,489,274 people whose personal information was exposed on August 13, 2025.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed December 21, 2025
Last reviewed July 22, 2026
Affected 3489274
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email