Oracle Breach: Ransom Demands Keep Coming Months Later
Oracle Breach: Ransom Demands Keep Coming Months Later
Updated: August 26, 2026
Table of Contents
- What Happened in the Oracle E-Business Suite Hack?
- Timeline: From First Access To Latest Update
- What Data Or Systems Were Affected
- Who Was Responsible (Confirmed Vs Alleged)
- How The Attack Worked
- Company Response And Customer Remediation
- Government, Law Enforcement, And Regulator Actions
- Financial, Legal, And Business Impact
- What Remains Unclear About the Oracle E-Business Suite Hack Still Generating Ransom Demands
- Who Were the Affected Parties
- Why This Incident Matters
- How Bright Defense Helps Reduce Risk
- Sources
What Happened in the Oracle E-Business Suite Hack?
A sprawling extortion campaign tied to the CL0P brand has targeted organizations that run Oracle’s E-Business Suite (EBS), with attackers claiming they stole data from victims’ EBS environments and then pressuring executives for payment. The campaign surfaced publicly in late September 2025 and continued into January 2026, with reports of ongoing ransom demands and new victim notifications.
Google Threat Intelligence Group (GTIG) and Mandiant said the extortion emails began on or before September 29, 2025, and followed “months of intrusion activity,” with exploitation activity observed as early as August 9, 2025, plus suspicious activity going back to July 10, 2025.
Oracle confirmed that customers received extortion emails, while reports differed on whether attackers relied on previously patched flaws or a then-unpatched weakness later tracked as CVE-2025-61882.
A continuous vulnerability management program can help organizations track newly exploited flaws, prioritize emergency patches and verify remediation across exposed enterprise systems.
Timeline: From First Access To Latest Update
GTIG described a two-part pattern involving intrusions into customer EBS environments followed by a large-volume extortion email campaign aimed at executives.
Key dated milestones, based on GTIG reporting:
- July 10, 2025: Suspicious activity tied to EBS targeting.
- August 9, 2025: Exploitation consistent with the campaign occurred as early as this date.
- September 29, 2025: Extortion email campaign began.
- October 3, 2025: Oracle acknowledged customers had received extortion emails.
- October 4 to October 5, 2025: CVE-2025-61882 published; Oracle issued an alert.
- October 6, 2025: CVE-2025-61882 added to CISA’s catalog.
- October 10 to October 11, 2025: GTIG published a detailed report and Oracle released a new patch.
- November to December 2025: Victim notifications expanded.
- December 5, 2025: Class action suit filed by a former Washington Post employee.
- January 14, 2026: Reports indicated the Oracle-related hack was still generating ransom demands.
What Data Or Systems Were Affected
Oracle E-Business Suite stores sensitive information, making it a target for data-theft extortion. GTIG indicated theft of sensitive data from EBS environments. Breach-notice filings indicate personal information exposure; for example, The Washington Post breach saw 9,720 affected individuals.
Who Was Responsible (Confirmed Vs Alleged)
GTIG attributed the extortion to a financially motivated actor under the CL0P brand, with overlaps to groups historically associated with CL0P. Reuters reported a ransomware group claiming affiliation with CL0P.
How The Attack Worked
GTIG stated the extortion campaign involved high-volume emails sent from compromised accounts, leveraging credentials sold in underground markets. Exploited vulnerabilities included CVE-2025-61882, a critical flaw affecting supported versions of Oracle E-Business Suite.
Company Response And Customer Remediation
Oracle recommended customers upgrade and noted possible exploitation of known vulnerabilities. Common remediation efforts involved credit monitoring and identity protection offers.
Government, Law Enforcement, And Regulator Actions
Government tracking reflects active exploitation. NVD’s records indicated various vulnerabilities entered CISA’s Known Exploited catalog with respective due dates for remediation.
Financial, Legal, And Business Impact
Ransom demands reached up to $50 million. Incident response and notification costs can add up, with delayed discovery and increased forensic scope leading to significant financial impact.
What Remains Unclear About the Oracle E-Business Suite Hack Still Generating Ransom Demands
The total victim count remains uncertain; estimations suggest more than 100 organizations affected. Oracle's attribution of vulnerabilities remains a contentious topic.
Who Were the Affected Parties
Organizations running Oracle EBS included:
- Harvard University
- Envoy Air (American Airlines subsidiary)
- Cox Enterprises
- University of Phoenix
- The Washington Post
- Korean Air related unit
Why This Incident Matters
The EBS campaign illustrates vulnerabilities in widely deployed enterprise software, highlighting issues related to attribution and swift remediation during active incidents.
How Bright Defense Helps Reduce Risk
Bright Defense offers targeted testing of ERP systems and continuous compliance programs to enhance protection against similar campaigns.
Sources
- Wall Street Journal — Oracle Hack Still Generating Ransom Demands ( January 14, 2026)
- Reuters — Oracle says hackers are trying to extort its customers ( October 3, 2025)
- Reuters — Google says hackers are sending extortion emails to executives ( October 2, 2025)
- Reuters — Washington Post says it is among victims of cyber breach tied to Oracle software ( November 6, 2025)
- Google Cloud Blog (GTIG and Mandiant) — Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign ( October 10, 2025)
- NVD (NIST) — CVE-2025-61882 detail page (published October 5, 2025)
- NVD (NIST) — CVE-2025-61884 detail page (includes KEV dates)
- Oracle — Security Alert for CVE-2025-61882
- Oracle — Security Alert for CVE-2025-61884
- Oracle — Critical Patch Update Advisory ( October 2025)
- Maine Attorney General Data Breach Notifications — The Washington Post filing (consumer notice November 12, 2025, total affected 9,720)
- Maine Attorney General Data Breach Notifications — GlobalLogic filing (consumer notice November 7, 2025, total affected 10,471)
- Maine Attorney General Data Breach Notifications — Cox Enterprises filing (consumer notice November 20, 2025, total affected 9,479)
- Maine Attorney General Data Breach Notifications — LKQ filing (consumer notice December 15, 2025, total affected 9,070)
- Politico — Former Washington Post employee launches class action suit after data breach ( December 5, 2025)
- SecurityWeek — Oracle says known vulnerabilities possibly exploited in extortion attacks ( October 10, 2025)
- TechCrunch — Hackers are sending extortion emails to executives after claiming Oracle apps data breach ( October 2, 2025)
- TechRepublic — Oracle extortion case cites demands up to $50 million ( October 2, 2025)