Desk live·
ForensicPost
Ransomware/Education/File 25-1012

A University’s Finance System, 1.3 Terabytes, and a Leak-Site Listing

Harvard confirmed a breach through the Oracle EBS zero-day, with around 1.3 TB reported exfiltrated. It was listed publicly on 12 October 2025.

Constructed geometry · not a chart of case data
TargetHarvard University
ActorCl0p
D. Kennedy10 min readConfidence: medium2 sources reviewed

Harvard University confirmed a data breach resulting from exploitation of CVE-2025-61882 in Oracle E-Business Suite, attributed to Cl0p, with reporting describing approximately 1.3 terabytes exfiltrated. The university was listed on the group’s leak site on 12 October 2025.

ERP At A University Is A Wider Dataset Than At A Company

A commercial ERP holds staff. A university’s holds staff, students, alumni donors, research grant administration and supplier relationships — the whole financial surface of an institution that functions simultaneously as an employer, an education provider, a research body and a fundraising operation.

It is the estate breadth this desk described at 26-0518 and 26-0305, reached through the single system that touches all of it.

Confirmation Is Worth More Than The Volume Figure

The 1.3 TB figure originates in reporting on the group’s claims and we treat it as one. The confirmation of a breach by the institution is the established fact, and it is the more useful one.

Universities disclosing quickly is not universal, and this desk has previously noted at 26-0107 that sectors handle this with commercial confidentiality where they can. An institution confirming while a campaign is still running gives its peers something actionable.

How we reported this

Compiled from public reporting, listed below. The volume figure derives from the attacking group and is labelled as a claim; the breach confirmation is the institution’s. Corrections: corrections@forensicpost.com.

Sources
  1. Harvard University data breach: Cl0p ransomware exploits Oracle E-Business Suite zero-dayRescana
  2. Clop’s new extortion wave hits Oracle E-Business SuiteBlackFog
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary