Business Context and Reporting Period
Company: Phoenix Education Partners, Inc. (subsidiary: The University of Phoenix, Inc.)
Filing Type: Form 8-K (Current Report)
Date of Report: December 2, 2025
Event: Disclosure of a cybersecurity incident involving the Oracle E-Business Suite (Oracle EBS) software platform.
Key Financial Metrics
This filing does not provide specific revenue, profit, cash flow, margin, debt, or liquidity figures. The report focuses on a non-financial operational event. However, the Company notes it will incur expenses in the fiscal year directly and indirectly related to the incident. The Company maintains a comprehensive cybersecurity insurance policy covering response, investigation, remediation, regulatory actions, business interruption, and legal proceedings, subject to deductibles, exclusions, and limits.
Material Changes and Incident Details
- Incident Timeline: The unauthorized third-party exploited a previously unknown software vulnerability in August 2025. The incident was detected on November 21, 2025. Patches were installed in October 2025 following their release.
- Data Compromised: Personal information including names, contact information, dates of birth, social security numbers, and bank account and routing numbers for numerous individuals.
- Operational Impact: The incident did not impact business operations or student programming. The Company believes the incident will not have a material adverse effect on its business operations or student programming as of the filing date.
- Current Status: Investigation is ongoing with leading third-party cybersecurity firms. The Company is unaware of any public dissemination of the data by the unauthorized third-party.
Guidance, Outlook, and Risks
Management Commentary: The Company is continuing to review impacted data and will provide required notifications to affected parties and regulatory entities. Expenses related to the event are expected to be incurred in the current fiscal year.
Risks and Contingencies:
- Potential discovery of additional information during the ongoing investigation.
- Impact on relationships with employers, employees, faculty, students, and governmental regulators.
- Legal, reputational, and financial risks, including potential regulatory inquiries and litigation.
- Remediation and additional costs associated with the investigation.
Forward-Looking Statements: The filing contains forward-looking statements regarding the extent and impact of the incident, insurance coverage, and financial effects, which are subject to risks and uncertainties that could cause actual results to differ materially.
Investor Verification Checklist
- Verify the scope of the data breach and the number of individuals affected once the investigation concludes.
- Monitor for updates on regulatory notifications and potential litigation arising from the incident.
- Review the specific deductibles, exclusions, and limits of the Company's cybersecurity insurance policy to assess potential out-of-pocket costs.
- Track the total expenses incurred related to the incident in future quarterly and annual reports.
- Assess any changes in the Company's risk factors in subsequent filings regarding cybersecurity threats.