Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
McKinsey partner says up to 50% of work hours could be transformed within the next 5 years

McKinsey partner says up to 50% of work hours could be transformed within the next 5 years

21 May 2026
Securing The Internet’s Humanity

Securing The Internet’s Humanity

21 May 2026
Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

21 May 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Dartmouth Data Breach Exposes 40,000 Social Security Numbers In Cl0p’s Oracle Rampage
Innovation

Dartmouth Data Breach Exposes 40,000 Social Security Numbers In Cl0p’s Oracle Rampage

Press RoomBy Press Room7 December 20255 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Dartmouth Data Breach Exposes 40,000 Social Security Numbers In Cl0p’s Oracle Rampage

Dartmouth College has confirmed that a three-day cyberattack in August compromised the personal information of more than 40,000 people, including Social Security numbers and financial account details, in what has become one of the most significant data breaches to hit higher education this year.

The attack, disclosed in breach notifications filed with state attorneys general last week, is part of a sweeping campaign that has hit more than one-hundred organizations worldwide, according to security researchers. The perpetrators exploited a previously unknown vulnerability in Oracle’s E-Business Suite, the enterprise software Dartmouth and thousands of other institutions use to manage everything from payroll to procurement.

The Cl0p ransomware gang has claimed responsibility for the campaign on its dark web leak site, where it has posted stolen data from multiple victims including Dartmouth. Security firms CrowdStrike and Google’s Threat Intelligence Group have independently attributed the exploitation campaign to Cl0p, with Google researchers noting overlap with infrastructure and tactics previously linked to the group.

For the victims receiving notification letters this month, the breach represents a textbook example of supply chain risk: Dartmouth did nothing wrong. No employee clicked a malicious link. No password was guessed. The college’s own systems were not directly hacked. Instead, attackers found a hidden flaw in software the institution trusted, and used it to steal files containing some of the most sensitive information an organization can hold.

The breach affected 31,742 New Hampshire residents and 12,701 Vermonters, according to filings with those states’ attorneys general. Dartmouth also filed breach notices in Maine, California and Texas, meaning the combined total exceeds 44,000, though the college has not disclosed a comprehensive figure. The compromised data includes names combined with Social Security numbers and, in some cases, bank account information.

“The breach involved the disclosure of names, combined with Social Security numbers, possibly bank accounts, and occurred in a three-day period in mid-August,” Vermont Attorney General Charity Clark told WCAX.

The attackers struck between August ninth and August twelfth, weeks before Oracle even knew the vulnerability existed. Google’s researchers confirmed that Cl0p had been exploiting the flaw, tracked as CVE-2025-61882, as a zero-day since at least early August, with suspicious reconnaissance activity dating back to July. The vulnerability carries a CVSS score of 9.8 out of 10, making it as severe as security flaws get.

Oracle did not issue a patch until October fourth, nearly two months after the initial attacks began. By then, the damage was done.

FBI Assistant Director Brett Leatherman called it a “stop what you’re doing and patch immediately” vulnerability in a LinkedIn post urging organizations to act. The Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalog on October sixth, mandating that federal agencies patch within days.

Dartmouth is not alone among elite universities. Harvard confirmed in October that attackers had accessed data from what a spokesperson described as “a small administrative unit” using the same Oracle flaw. The University of Pennsylvania disclosed a similar breach last week, affecting at least 1,488 individuals according to state filings. Cl0p has also claimed victims including The Washington Post, Logitech and American Airlines subsidiary Envoy Air posting stolen data to its leak site and making it available for download via torrent.

For those familiar with Cl0p’s tactics, the Oracle campaign follows a well-established playbook. In 2023, the group exploited a zero-day vulnerability in Progress Software’s MOVEit file transfer tool, ultimately compromising more than 2,000 organizations and exposing the personal data of tens of millions of individuals, according to researchers tracking the campaign. The ransomware response firm Coveware estimated Cl0p earned roughly $75 million from MOVEit alone.

The group’s strategy is consistent: identify widely used enterprise software, find or acquire a zero-day exploit, then hit as many targets as possible before patches are available. Researchers at Cybereason, who have been tracking the Oracle campaign, described Cl0p’s methodology: “CL0P often conducts extensive reconnaissance, custom code development, CVE attack chaining and coordinates mass scale victimization in rapid, iterative, and sometimes parallel succession.”

What makes zero-day attacks particularly difficult to defend against is that organizations have no warning. Traditional security measures — firewalls, antivirus software, employee training — cannot stop an attacker exploiting a vulnerability that no one knows exists. The flaw was in Oracle’s code. Dartmouth was simply running the software as designed.

“This incident was not the result of any ‘phishing’ attack on a member of the Dartmouth community or any other action or inaction on Dartmouth’s part,” college spokesperson Jana Barnello said.

Clark, the Vermont attorney general, said the incident should prompt legislative action. “Our Legislature in Vermont has had many opportunities to pass a comprehensive data privacy law that would hopefully reduce the number of data breaches we see and also minimize the harm that could potentially occur if there is a data breach,” she said. “That really, in my mind, is the place we should be focusing.”

Dartmouth has implemented all publicly available patches from Oracle and established a dedicated assistance line for affected individuals. The college is offering one year of complimentary identity monitoring through Experian IdentityWorks to anyone whose Social Security number was exposed. Enrollment must be completed by February 28, 2026.

For anyone who received a notification letter, the immediate steps are straightforward: enroll in the free credit monitoring, place fraud alerts or security freezes with the three major credit bureaus, and monitor financial statements closely for the next 12 to 24 months. Social Security numbers do not expire. Once stolen, they retain value to criminals indefinitely.

The larger question is how organizations can protect themselves when the software they rely on contains flaws no one has yet discovered. The answer, uncomfortable as it may be, is that complete protection is impossible. What matters is how quickly vulnerabilities are patched once known, how effectively organizations monitor for signs of compromise, and how transparently they communicate with victims when breaches occur.

Cl0p ransomware computer security Dartmouth College data breach Dartmouth hack 2025 Data Breach Ivy League cyberattack Oracle CVE-2025-61882 Oracle E-Business Suite vulnerability Social Security number breach zero-day exploit university
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Securing The Internet’s Humanity

Securing The Internet’s Humanity

21 May 2026
Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

21 May 2026
Why Complexity Is The Insider Threat Hiding In Plain Sight

Why Complexity Is The Insider Threat Hiding In Plain Sight

21 May 2026
2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

21 May 2026
​How AI Is Changing The Economics Of Integration

​How AI Is Changing The Economics Of Integration

21 May 2026
Airbnb CEO Brian Chesky Called Chinese AI Fast And Cheap. Now, Congress Wants Answers

Airbnb CEO Brian Chesky Called Chinese AI Fast And Cheap. Now, Congress Wants Answers

21 May 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
MacKenzie Scott snubbed from top donors list despite  billion philanthropy

MacKenzie Scott snubbed from top donors list despite $7 billion philanthropy

21 May 20262 Views
Why Complexity Is The Insider Threat Hiding In Plain Sight

Why Complexity Is The Insider Threat Hiding In Plain Sight

21 May 20261 Views
‘We do not want humans to have the same fate as dinosaurs’: SpaceX IPO reads like Hollywood fantasy version of the future

‘We do not want humans to have the same fate as dinosaurs’: SpaceX IPO reads like Hollywood fantasy version of the future

21 May 20260 Views
2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

21 May 20262 Views

Recent Posts

  • McKinsey partner says up to 50% of work hours could be transformed within the next 5 years
  • Securing The Internet’s Humanity
  • Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’
  • Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do
  • MacKenzie Scott snubbed from top donors list despite $7 billion philanthropy

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
McKinsey partner says up to 50% of work hours could be transformed within the next 5 years

McKinsey partner says up to 50% of work hours could be transformed within the next 5 years

21 May 2026
Securing The Internet’s Humanity

Securing The Internet’s Humanity

21 May 2026
Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

21 May 2026
Most Popular
Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

21 May 20261 Views
MacKenzie Scott snubbed from top donors list despite  billion philanthropy

MacKenzie Scott snubbed from top donors list despite $7 billion philanthropy

21 May 20262 Views
Why Complexity Is The Insider Threat Hiding In Plain Sight

Why Complexity Is The Insider Threat Hiding In Plain Sight

21 May 20261 Views

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.