The University of Phoenix has today begun notifying over 3.4 million individuals that their data was stolen in a hack by the notorious ransomware gang known as Cl0p. Yeah. That Cl0p. Clearly they’ve been busy this year by being naughty and not nice.
Rebecca Moody, Head of Data Research at Comparitech had this to say:
“According to our data, this is the fourth-largest ransomware attack in the world this year (based on records affected). It highlights the ongoing threat that companies face via ransomware — and not just via attacks on their own systems. Attacks on third parties like Oracle often give hackers access to a multitude of companies (and their data) via one central source. And as Clop is now rumored to be exploiting a new vulnerability through another software company (Gladinet CentreStack), its devastating data breaches look set to continue well into 2026.”
Paul Bischoff, Consumer Privacy Advocate at Comparitech follows with this:
“Clop has been on a rampage this year, targeting zero-day vulnerabilities in software used by large enterprises. Specifically, it targets Oracle’s E-Business Suite and the Cleo file transfer software. This attack on the University of Phoenix is most likely related to the former.
According to our research, Clop has claimed the third-most data breaches of any ransomware gang in 2025.”
See: https://www.comparitech.com/news/ransomware-roundup-november-2025/
Chris Hauk, Consumer Privacy Champion at Pixel Privacy adds this:
“This is just the latest data breach of US universities, with Harvard University, the University of Pennsylvania, and Princeton University having been compromised by hackers, who stole the personal information of donors, students, alumni, staff, and faculty. We will surely see this trend continue, as bad actors around the world look to increase the size of their data cache from US educational institutions.
I would urge any individuals affected by this breach to take advantage of the university’s offer of free identity protection services, fraud reimbursement policy, one year of credit monitoring, identity theft recovery, and dark web monitoring. This will give them a leg up in detecting if bad actors are attempting to use the data gathered from the breach for nefarious purposes, as the information stolen includes dates of birth, social security numbers, and bank account and routing numbers.”
Finally, Ensar Seker, CISO of SOCRadar had this to say:
“This breach underscores a troubling pattern we’ve seen throughout 2025: threat actors like Clop continuing to weaponize zero-day vulnerabilities and mass data exfiltration campaigns against large, centralized educational platforms with insufficient segmentation between student, staff, and supplier data.
Universities remain attractive targets due to sprawling digital ecosystems and a mix of legacy and cloud infrastructure. Attackers exploit these complexities often entering through third-party vendors or outdated portals—and move laterally across systems before exfiltrating millions of records. The fact that Clop accessed data tied to nearly 3.5 million individuals suggests minimal micro-segmentation or inadequate identity and access management (IAM) protocols.
Clop’s playbook is not new. They’ve repeatedly exploited MOVEit and other file transfer software to compromise vast amounts of sensitive data. Their ransomware operations are increasingly interwoven with pure data theft and extortion, leveraging leak sites and public shaming campaigns to pressure victims. In this case, the potential inclusion of personal data from students and faculty introduces FERPA, HIPAA, and contractual risk dimensions for University of Phoenix.
Given the scale and societal impact of this attack, it’s time for educational institutions to be held to the same cybersecurity standards as critical infrastructure. That includes mandatory vendor security assessments, data minimization strategies, and endpoint telemetry across hybrid environments. Breaches like this are not just IT issues,they’re national resilience risks when millions of PII records are involved.
Transparent forensic reporting, mass notification procedures, and proactive credit monitoring must be prioritized. From a policy standpoint, it’s time for federal regulators to reevaluate breach notification thresholds and introduce industry-wide frameworks tailored for academia.”
While Cl0p isn’t the only ransomware gang out there, they’ve clearly been busy. Which doesn’t bode well for any of us in 2026.
Review: TP-Link Tapo C560WS Security Camera
Posted in Commentary with tags TP-Link on December 31, 2025 by itnerdOutdoor security cameras are the in thing at the moment. For example here in Toronto, they are often used to watch over cars because car theft is a problem here, or to secure your home from break and enter scumbags. So I’m having a look at the TP-Link Tapo C560WS to see if this a viable option for your security camera needs. First some specs to get you started:
Resolution:4K
Connectivity: 2.4GHz + 5GHz Wi-Fi and Ethernet
Night Vision: IR + Full Color
Field of view: 326 degrees (horizontal), 53 degrees (vertical)
Storage: Up to 512GB via microSD + optional cloud storage
Two-way speaker: Yes
IP rating: IP66 (Water resistant against powerful jets)
Here’s a look at the camera itself:
It looks pretty much like any other security camera. There’s minimal branding on it.
There’s the speaker behind the camera:
Here’s the front of the camera with the IR illuminators that’s below the lens for night vision purposes and spotlight for lighting purposes. At the top is a rubber cover that behind it has the microSD card slot and a reset button.
So there is a cable that has two connections. When I saw the Ethernet connector, I thought “Oh this does Power Over Ethernet”. Well, it doesn’t. That’s a bit of a disappointment as I would rather run one cable to the camera rather than two to a camera. On top of that, for the best possible security you should connect this camera via Ethernet as car thieves in Toronto have been found to be using WiFi jammers to disable security cameras that are on WiFi. That’s clearly not going to happen if your camera is on Ethernet. The other connector is the power connector which appears to be a BNC or barrel style connector. That makes life easier if you have to run a power cable to the camera. Though I will note that the power adapter that comes with the camera has a pretty long cable.
Also included in the box is all the mounting hardware and screws as well as the waterproofing hardware for the cables.
Physically mounting the camera was pretty easy as I mounted it on my balcony. Then I used the Tapo app which is available for iOS and Android to get it onto my WiFi. I ended up using 2.4 GHz WiFi as it had better signal strength versus the 5 GHz network. I could then use the Tapo app to control it.
Let’s start with the visuals. I always got clear and detailed image when I tested it. Here’s a still image from the camera:
And here’s a video test:
One thing that I should point out is that I had the camera set to auto in terms of resolution. But the camera kicked into 4K mode for this clip. I could pick out snowflakes in the recording as well as footprints on the ground from 14 stories up. Very impressive!
I then did the same test at night. Here’s the still image:
And here’s the video:
I also tried the spotlight and it’s pretty bright based on this image:
What it also shows is that when spring comes around, I need to clean the glass on my balcony.
One thing that I should note is that black and white mode never triggered on this camera. I am guessing that this is because there was enough light to make going into that mode something that wasn’t required. But having said that, these pictures are outstanding.
Other highlights:
The best thing about the TP-Link Tapo C560WS is the price. I found it for $120 CAD on Amazon. At that price, you could forgive the fact that it that it doesn’t have Power Over Ethernet for the best possible deployment. But if you look past that, this is a great choice for a security camera. It is easy to set up, has great video and audio, and has a variety of storage options. All for a pretty unbeatable price.
Leave a comment »