Back to overview
Oracle logo
oracle.com
Oracle
Confidence HighSep 29, 2025oracle.com

Cl0p Ransomware Group Exploits Oracle E-Business Suite Zero-Day

PatternExternal actor · Malware · Availability impact

The Cl0p ransomware group launched a large-scale extortion campaign by exploiting a zero-day vulnerability (possibly CVE-2025-61882) in Oracle's E-Business Suite (EBS). This led to critical data breaches for dozens of large corporations, with over 100 companies allegedly impacted. The exploitation activity was observed as early as August 9, 2025, weeks before a patch was available, and suspicious activity dated back to July 10, 2025. The threat actors exfiltrated a significant amount of data from impacted organizations and sent high-volume emails to executives demanding payment.

Signal date
Sep 29, 2025
Updated
Jun 19, 2026
Confidence
High
Sources
1 source
oracle.com logo

Oracle

Sector
Finance and Insurance
Signals
1 linked

Signal context

First seen: Sep 29, 2025

Last updated: Jun 19, 2026

Status: Public signal

Key points

  • Cl0p ransomware group exploited a zero-day vulnerability in Oracle E-Business Suite.
  • Over 100 companies were allegedly impacted, with data exfiltrated.
  • Exploitation activity was observed from July 2025, with a widespread campaign starting September 29, 2025.

Signal analysis

Beta

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Affected organization
Oracle logo
Oracle

Sector: Finance and Insurance

Likely country: Location not provided

Estimated
Threat source
Malware, Hacking activity

Watch ransomware, endpoint compromise and business interruption exposure.

  • Source type: outside the affected organization
Business impact
Potential operational disruption

Impact area: Availability

Trend context
92 signals with similar action pattern
  • 21 signals in the same sector
  • 22 signals with the same likely impact area
  • 1 signal linked to this organization/domain
Mentioned entities
OracleCl0p Ransomware Group Exploits OracleE-Business Suite Zero-Day The Cl0pCVE-2025-61882OracleE-Business SuiteEBSCl0pOracle E-Business Suite. OverExploitation

External sources

Related signals

Grouped by why the signal is relevant.

ahisd.net logoAhisdJun 26, 2026
Same sectorSame action patternSame impact area

Alamo Heights ISD Reports Data Breach Following Ransomware Attack

Alamo Heights Independent School District (ISD) reported a data breach impacting over 26,000 people, disclosed to the Texas Attorney General's office on June 25, 2026 (published June 26, 2026 UTC). The breach was linked to a ransomware attack by the Qilin group, which occurred on April 9, 2026. The compromised information included names, Social Security numbers, driver's license numbers, and bank and medical information.

ayabank.com logoAyabankJun 23, 2026
Same sectorSame action patternSame impact area

AYA BANK Hit by Lapsus$ Ransomware Attack

AYA BANK, a prominent financial institution in Myanmar, fell victim to a ransomware attack by the Lapsus$ group, discovered on June 23, 2026. Lapsus$ claimed to have stolen over 120 gigabytes of data, including a full dump and PII, and threatened to sell it if a ransom was not paid. AYA Bank acknowledged a breach of an older application portal exposing some customer information but stated its core financial networks remained secure.

legendsmn.com logoLegendsmnJun 19, 2026
Same sectorSame action patternSame impact area

Legendary Home Services Breached by NightSpire Ransomware

On June 19, 2026, US home services company Legendary Home Services (operating as legendsmn.com) was listed as a victim by the NightSpire ransomware group. The breach was publicly identified on ransomware-tracking platforms. Initial reports indicate a ransomware attack, but the exact number of affected individuals and specific categories of data compromised (such as names, addresses, phone numbers, email addresses, or payment information) remain unknown.

oracle.com logoOracleJun 10, 2026
Same companySame action pattern

Oracle PeopleSoft Zero-Day Exploited by ShinyHunters, Advisory Published

Oracle published a security advisory on June 10, 2026, for CVE-2026-35273, a critical remote code execution flaw in PeopleSoft Enterprise PeopleTools. This vulnerability was actively exploited as a zero-day by the ShinyHunters cybercrime group in a campaign that ran from May 27 to June 9, 2026. The attacks compromised over 100 organizations, primarily colleges and universities, leading to data theft.

assuranceamerica.com logoAssuranceamericaJun 27, 2026
Same sectorSame action pattern

AssuranceAmerica Data Breach Exposes Driver, Insurance, and Social Security Data

A data breach at AssuranceAmerica may impact over 1.1 million people across seven states. Notices were sent to residents on June 26, 2026. An unauthorized third party accessed the company's computer systems and copied data files, including customer names, contact information, automobile insurance policies, driver/vehicle information, claims data, driver's license numbers, tax ID information, and potentially Social Security numbers. The incident was detected on March 17, 2026, after malicious activity targeting an employee was found on March 16, 2026.

xsolis.com logoXsolisJun 26, 2026
Same sectorSame action pattern

Healthcare AI Company Xsolis Suffers Data Breach Impacting 1.4 Million Individuals

Healthcare AI company Xsolis disclosed a data breach affecting nearly 1.4 million individuals. The incident stemmed from a targeted phishing attack on January 20, 2026, which gave attackers unauthorized access to files containing sensitive patient information. The compromised data potentially includes names, dates of birth, Social Security numbers, health insurance details, and medical treatment records. Xsolis confirmed the incident has been contained and is notifying affected individuals, offering free credit monitoring.