Oracle Breach: Ransom Demands Keep Coming Months Later

Oracle Breach: Ransom Demands Keep Coming Months Later

Updated: August 26, 2026

Table of Contents

  1. What Happened in the Oracle E-Business Suite Hack?
  2. Timeline: From First Access To Latest Update
  3. What Data Or Systems Were Affected
  4. Who Was Responsible (Confirmed Vs Alleged)
  5. How The Attack Worked
  6. Company Response And Customer Remediation
  7. Government, Law Enforcement, And Regulator Actions
  8. Financial, Legal, And Business Impact
  9. What Remains Unclear About the Oracle E-Business Suite Hack Still Generating Ransom Demands
  10. Who Were the Affected Parties
  11. Why This Incident Matters
  12. How Bright Defense Helps Reduce Risk
  13. Sources

What Happened in the Oracle E-Business Suite Hack?

A sprawling extortion campaign tied to the CL0P brand has targeted organizations that run Oracle’s E-Business Suite (EBS), with attackers claiming they stole data from victims’ EBS environments and then pressuring executives for payment. The campaign surfaced publicly in late September 2025 and continued into January 2026, with reports of ongoing ransom demands and new victim notifications.
Google Threat Intelligence Group (GTIG) and Mandiant said the extortion emails began on or before September 29, 2025, and followed “months of intrusion activity,” with exploitation activity observed as early as August 9, 2025, plus suspicious activity going back to July 10, 2025.
Oracle confirmed that customers received extortion emails, while reports differed on whether attackers relied on previously patched flaws or a then-unpatched weakness later tracked as CVE-2025-61882.
A continuous vulnerability management program can help organizations track newly exploited flaws, prioritize emergency patches and verify remediation across exposed enterprise systems.

Timeline: From First Access To Latest Update

GTIG described a two-part pattern involving intrusions into customer EBS environments followed by a large-volume extortion email campaign aimed at executives.

Key dated milestones, based on GTIG reporting:

What Data Or Systems Were Affected

Oracle E-Business Suite stores sensitive information, making it a target for data-theft extortion. GTIG indicated theft of sensitive data from EBS environments. Breach-notice filings indicate personal information exposure; for example, The Washington Post breach saw 9,720 affected individuals.

Who Was Responsible (Confirmed Vs Alleged)

GTIG attributed the extortion to a financially motivated actor under the CL0P brand, with overlaps to groups historically associated with CL0P. Reuters reported a ransomware group claiming affiliation with CL0P.

How The Attack Worked

GTIG stated the extortion campaign involved high-volume emails sent from compromised accounts, leveraging credentials sold in underground markets. Exploited vulnerabilities included CVE-2025-61882, a critical flaw affecting supported versions of Oracle E-Business Suite.

Company Response And Customer Remediation

Oracle recommended customers upgrade and noted possible exploitation of known vulnerabilities. Common remediation efforts involved credit monitoring and identity protection offers.

Government, Law Enforcement, And Regulator Actions

Government tracking reflects active exploitation. NVD’s records indicated various vulnerabilities entered CISA’s Known Exploited catalog with respective due dates for remediation.

Financial, Legal, And Business Impact

Ransom demands reached up to $50 million. Incident response and notification costs can add up, with delayed discovery and increased forensic scope leading to significant financial impact.

What Remains Unclear About the Oracle E-Business Suite Hack Still Generating Ransom Demands

The total victim count remains uncertain; estimations suggest more than 100 organizations affected. Oracle's attribution of vulnerabilities remains a contentious topic.

Who Were the Affected Parties

Organizations running Oracle EBS included:

Why This Incident Matters

The EBS campaign illustrates vulnerabilities in widely deployed enterprise software, highlighting issues related to attribution and swift remediation during active incidents.

How Bright Defense Helps Reduce Risk

Bright Defense offers targeted testing of ERP systems and continuous compliance programs to enhance protection against similar campaigns.

Sources

  1. Wall Street Journal — Oracle Hack Still Generating Ransom Demands ( January 14, 2026)
  2. Reuters — Oracle says hackers are trying to extort its customers ( October 3, 2025)
  3. Reuters — Google says hackers are sending extortion emails to executives ( October 2, 2025)
  4. Reuters — Washington Post says it is among victims of cyber breach tied to Oracle software ( November 6, 2025)
  5. Google Cloud Blog (GTIG and Mandiant) — Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign ( October 10, 2025)
  6. NVD (NIST) — CVE-2025-61882 detail page (published October 5, 2025)
  7. NVD (NIST) — CVE-2025-61884 detail page (includes KEV dates)
  8. Oracle — Security Alert for CVE-2025-61882
  9. Oracle — Security Alert for CVE-2025-61884
  10. Oracle — Critical Patch Update Advisory ( October 2025)
  11. Maine Attorney General Data Breach Notifications — The Washington Post filing (consumer notice November 12, 2025, total affected 9,720)
  12. Maine Attorney General Data Breach Notifications — GlobalLogic filing (consumer notice November 7, 2025, total affected 10,471)
  13. Maine Attorney General Data Breach Notifications — Cox Enterprises filing (consumer notice November 20, 2025, total affected 9,479)
  14. Maine Attorney General Data Breach Notifications — LKQ filing (consumer notice December 15, 2025, total affected 9,070)
  15. Politico — Former Washington Post employee launches class action suit after data breach ( December 5, 2025)
  16. SecurityWeek — Oracle says known vulnerabilities possibly exploited in extortion attacks ( October 10, 2025)
  17. TechCrunch — Hackers are sending extortion emails to executives after claiming Oracle apps data breach ( October 2, 2025)
  18. TechRepublic — Oracle extortion case cites demands up to $50 million ( October 2, 2025)