Skip to main content
Back to overview
Medium

Logitech Confirms Data Breach as Part of Cl0p Oracle EBS Campaign

Logitech disclosed a data breach on November 17, 2025, confirming it was impacted by a hacking and extortion campaign targeting customers of Oracle's E-Business Suite (EBS).

Key points

  • Logitech disclosed a data breach on November 17, 2025.
  • The breach was linked to the Cl0p ransomware group's campaign exploiting a zero-day vulnerability in Oracle E-Business Suite.
  • An unauthorized third party copied data from Logitech's internal IT systems.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Hacking activity

03

Potential impact

Potential operational disruption

Confidentiality, Availability

Published
Nov 17, 2025
Updated
Jun 25, 2026
Confidence
Medium
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Hacking activity

Watch ransomware, endpoint compromise and business interruption exposure.

  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

LogitechData DisclosurePart of Cl0p Oracle EBSCampaign LogitechOracleE-Business SuiteEBSThe Cl0pLogitechCl0p

Quick context

Questions about this signal

What happened in this signal?

Logitech disclosed a data breach on November 17, 2025, confirming it was impacted by a hacking and extortion campaign targeting customers of Oracle's E-Business Suite (EBS). The company stated that an unauthorized third party exploited a zero-day vulnerability in a third-party software platform to copy certain data from its internal IT systems. The Cl0p ransomware group claimed responsibility for the attack, which allegedly involved the exfiltration of approximately 1.8 terabytes of data. Logitech indicated that the compromised data likely included limited information about employees, consumers, customers, and suppliers, but did not believe sensitive personal information like national ID numbers or credit card information was housed in the impacted system. The company initiated an investigation with external cybersecurity firms and applied patches for the zero-day vulnerability.

When was this signal reported?

Shadow Tier lists Nov 17, 2025 as the signal date.

Which organization is connected to this signal?

Logitech is the organization connected to this public signal.

Explore Logitech
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents