Oracle links extortion campaign to bugs addressed in July patch

Oracle links extortion campaign to bugs addressed in July patch

Oracle investigates a data breach linked to the Clop ransomware gang that involves stolen information from its E-Business Suite. Customers are being extorted through emails demanding payments or threatening to release or sell their data on the dark web. #Clop #OracleEBusinessSuite

Keypoints

  • Oracle confirms a potential breach involving its E-Business Suite and is urging customers to apply the latest patches.
  • The Clop ransomware gang has stolen data and is extorting victims with threats to publish or sell the information.
  • Incident responders from Mandiant and GTIG are investigating the campaign, which started around September 29.
  • The attackers have used previously known vulnerabilities that were addressed in Oracle’s July 2025 Critical Patch Update.
  • Clop has a history of exploiting vulnerabilities in file transfer software to conduct high-profile data thefts.

Read More: https://therecord.media/oracle-links-extortion-campaign-to-patched-vulnerabilities