Yes — Parexel International, LLC notified individuals after a third-party Oracle cloud incident. Consumer / regulator letters state Parexel detected suspicious activity on October 4, 2025 in a portion of its Oracle OCI E-Business Suite environment hosted by Oracle. Investigation tied the activity to a zero-day Oracle announced October 5, 2025. Parexel says the incident was limited to the vendor environment and that Parexel’s own network was not compromised.
The Texas Attorney General portal lists 1,203 Texans affected (published December 17, 2025), with U.S. Mail notice, covering names, DOB, SSNs / national IDs, and financial / payment-card numbers (without CVV) provided in connection with employment.
This post is the Texas-specific Parexel notice, not a national Oracle MDL roundup. Neville v. Parexel (1:26-cv-00873, W.D. Tex, filed April 8, 2026) was later administratively closed and consolidated into In re Oracle Corporation Data Breach Litigation (1:25-cv-01805).

What Happened
| Field | Detail |
|---|---|
| Entity | Parexel International, LLC (parexel.com) — clinical research org (NC HQ; Texas residents noticed) |
| Vector | Oracle OCI E-Business Suite zero-day (vendor-hosted) |
| Detected | October 4, 2025 |
| Texans affected | 1,203 (Texas OAG) · notice Yes / U.S. Mail |
| Data | Employment-related name, DOB, SSN/national ID, financial / card numbers (no CVV) |
| Litigation | Neville 1:26-cv-00873 (filed Apr 8, 2026) → consolidated into Oracle MDL 1:25-cv-01805 (filed Nov 10, 2025) |

Independent Cybersecurity Audit
EmailMeNow audit of parexel.com on August 5, 2026. 100% is the ideal. Scores measure Parexel’s public domain — not Oracle’s cloud tenancy.
| Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|
| parexel.com | 54% | 50% | 15% | 45% | Average |

Key findings: 54% overall; recurring 15% transport gap; spoofed “Parexel HR / Oracle incident” mail remains a risk for noticed employees.
Audit link: parexel.com
Website-tech · blacklist · lookalikes · MFA
| Check | Result (Aug 5, 2026) |
|---|---|
| Website-tech | Platform undetected; Sectigo TLS |
| Blacklist | Clear on checked mail/domain lists (CDN SPFBL notes only) |
| Cybersquat | 25 lookalikes to review (parexeel.com, parexel.net, …); several brand redirects |
| YubiKey / open TOTP | Not documented on public consumer pages → Unevaluated |
Priority Actions
If you received a Parexel / Oracle-related employee letter: Enroll in monitoring only via the letter; freeze credit when SSN was listed; ignore unexpected “re-verify payroll” links.
For Oracle EBS customers in Texas: Track vendor advisories separately from your own DMARC/MTA-STS posture toward 100%.
Related Trackers
- Resource Corp of America OCR breach
- Texas healthcare breaches 2026
- Texas OAG YTD dashboard
- All state AG trackers
Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting.
Sources: Texas OAG — Data Security Breach Reports · Mass. AG — Parexel notice packet · CourtListener — Neville v. Parexel · CourtListener — In re Oracle 1:25-cv-01805 · EmailMeNow audit — parexel.com