Oracle EBS Hack Impacts Over 100 Organizations as Firms Assess Data Breach Exposure

Related

KDDI Confirms Zero-Day Exploit Behind Breach Affecting 12 Million People

What happened KDDI has updated its earlier breach disclosure, confirming...

Aflac Japan Data Breach Impacts 4.38 Million Customers and Agents

What happened Aflac Life Insurance Japan disclosed a data breach...

Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day Attacks

What happened Nissan disclosed a data breach affecting current and...

KDDI Breach Exposes Up to 14.2 Million Email Logins at Six ISPs

What happened Japanese telecommunications operator KDDI disclosed a data breach...

Xsolis Data Breach Affects 1.4 Million Individuals

What happened Healthcare technology company Xsolis disclosed a data breach...

Share

What happened

A large-scale cyberattack targeting Oracle E-Business Suite (EBS) customers resulted in data theft and extortion attempts affecting more than 100 organizations across multiple industries. The campaign has been attributed to the Cl0p ransomware and extortion group, which exploited zero-day vulnerabilities in Oracle’s enterprise software to access sensitive data stored by victim organizations. Attackers later published torrent files on a leak site containing data allegedly stolen from victims who refused to pay ransom demands. While many affected companies confirmed data breaches and began notifying impacted individuals, several major firms — including Broadcom, Bechtel, Estée Lauder, and Abbott Laboratories — have not issued public statements regarding potential impact or ongoing investigations. 

Who is affected

Organizations using Oracle E-Business Suite across sectors such as technology, finance, manufacturing, and energy are affected, along with individuals whose data may have been stored within compromised enterprise systems. 

Why CISOs should care

The incident highlights the scale of third-party software compromise, where exploitation of widely used enterprise platforms can expose large volumes of data across multiple organizations simultaneously. 

3 practical actions

  1. Assess Oracle EBS exposure. Identify systems using Oracle EBS and evaluate potential risk from the campaign. 
  2. Investigate potential data access. Review logs and indicators for unauthorized access to enterprise data stored in EBS environments. 
  3. Monitor extortion leak sites. Check whether organizational data appears in publicly released datasets. 

For more coverage of major security incidents affecting organizations worldwide, explore our reporting on Data Breaches.

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.