# Oracle Breach: Ransom Demands Keep Coming Months Later

**Updated:** August 26, 2026

## Table of Contents

01. [What Happened in the Oracle E-Business Suite Hack?](#what-happened-in-the-oracle-e-business-suite-hack)  
02. [Timeline: From First Access To Latest Update](#timeline-from-first-access-to-latest-update)  
03. [What Data Or Systems Were Affected](#what-data-or-systems-were-affected)  
04. [Who Was Responsible (Confirmed Vs Alleged)](#who-was-responsible-confirmed-vs-alleged)  
05. [How The Attack Worked](#how-the-attack-worked)  
06. [Company Response And Customer Remediation](#company-response-and-customer-remediation)  
07. [Government, Law Enforcement, And Regulator Actions](#government-law-enforcement-and-regulator-actions)  
08. [Financial, Legal, And Business Impact](#financial-legal-and-business-impact)  
09. [What Remains Unclear About the Oracle E-Business Suite Hack Still Generating Ransom Demands](#what-remains-unclear-about-the-oracle-e-business-suite-hack-still-generating-ransom-demands)  
10. [Who Were the Affected Parties](#who-were-the-affected-parties)  
11. [Why This Incident Matters](#why-this-incident-matters)  
12. [How Bright Defense Helps Reduce Risk](#how-bright-defense-helps-reduce-risk)  
13. [Sources](#sources)

## What Happened in the Oracle E-Business Suite Hack?  
A sprawling extortion campaign tied to the **CL0P** brand has targeted organizations that run Oracle’s E-Business Suite (EBS), with attackers claiming they stole data from victims’ EBS environments and then pressuring executives for payment. The campaign surfaced publicly in late **September 2025** and continued into **January 2026**, with reports of ongoing ransom demands and new victim notifications.    
Google Threat Intelligence Group (GTIG) and Mandiant said the extortion emails began on or before **September 29, 2025**, and followed “months of intrusion activity,” with exploitation activity observed as early as **August 9, 2025**, plus suspicious activity going back to **July 10, 2025**.    
Oracle confirmed that customers received extortion emails, while reports differed on whether attackers relied on previously patched flaws or a then-unpatched weakness later tracked as **CVE-2025-61882.**  
A [continuous vulnerability management program](/content/resources/embracing-continuous-vulnerability-management-program/index.html) can help organizations track newly exploited flaws, prioritize emergency patches and verify remediation across exposed enterprise systems.

## Timeline: From First Access To Latest Update

GTIG described a two-part pattern involving intrusions into customer EBS environments followed by a large-volume extortion email campaign aimed at executives.

Key dated milestones, based on GTIG reporting:

- **July 10, 2025:** Suspicious activity tied to EBS targeting.
- **August 9, 2025:** Exploitation consistent with the campaign occurred as early as this date.
- **September 29, 2025:** Extortion email campaign began.
- **October 3, 2025:** Oracle acknowledged customers had received extortion emails.
- **October 4 to October 5, 2025:** **CVE-2025-61882** published; Oracle issued an alert.
- **October 6, 2025:** **CVE-2025-61882** added to CISA’s catalog.
- **October 10 to October 11, 2025:** GTIG published a detailed report and Oracle released a new patch.
- **November to December 2025:** Victim notifications expanded.
- **December 5, 2025:** Class action suit filed by a former Washington Post employee.
- **January 14, 2026:** Reports indicated the Oracle-related hack was still generating ransom demands.

## What Data Or Systems Were Affected

Oracle E-Business Suite stores sensitive information, making it a target for data-theft extortion. GTIG indicated theft of sensitive data from EBS environments. Breach-notice filings indicate personal information exposure; for example, The Washington Post breach saw **9,720** affected individuals.

## Who Was Responsible (Confirmed Vs Alleged)

GTIG attributed the extortion to a financially motivated actor under the **CL0P** brand, with overlaps to groups historically associated with CL0P. Reuters reported a ransomware group claiming affiliation with **CL0P**.

## How The Attack Worked

GTIG stated the extortion campaign involved high-volume emails sent from compromised accounts, leveraging credentials sold in underground markets. Exploited vulnerabilities included **CVE-2025-61882**, a critical flaw affecting supported versions of Oracle E-Business Suite.

## Company Response And Customer Remediation

Oracle recommended customers upgrade and noted possible exploitation of known vulnerabilities. Common remediation efforts involved credit monitoring and identity protection offers.

## Government, Law Enforcement, And Regulator Actions

Government tracking reflects active exploitation. NVD’s records indicated various vulnerabilities entered CISA’s Known Exploited catalog with respective due dates for remediation.

## Financial, Legal, And Business Impact

Ransom demands reached up to **$50 million**. Incident response and notification costs can add up, with delayed discovery and increased forensic scope leading to significant financial impact.

## What Remains Unclear About the Oracle E-Business Suite Hack Still Generating Ransom Demands

The total victim count remains uncertain; estimations suggest more than **100** organizations affected. Oracle's attribution of vulnerabilities remains a contentious topic.

## Who Were the Affected Parties

Organizations running Oracle EBS included:

- Harvard University
- Envoy Air (American Airlines subsidiary)
- Cox Enterprises
- University of Phoenix
- The Washington Post
- Korean Air related unit

## Why This Incident Matters

The EBS campaign illustrates vulnerabilities in widely deployed enterprise software, highlighting issues related to attribution and swift remediation during active incidents.

## How Bright Defense Helps Reduce Risk

Bright Defense offers targeted testing of ERP systems and continuous compliance programs to enhance protection against similar campaigns.

## Sources

01. Wall Street Journal — Oracle Hack Still Generating Ransom Demands ( **January 14, 2026**)
02. Reuters — Oracle says hackers are trying to extort its customers ( **October 3, 2025**)
03. Reuters — Google says hackers are sending extortion emails to executives ( **October 2, 2025**)
04. Reuters — Washington Post says it is among victims of cyber breach tied to Oracle software ( **November 6, 2025**)
05. Google Cloud Blog (GTIG and Mandiant) — Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign ( **October 10, 2025**)
06. NVD (NIST) — **CVE-2025-61882** detail page (published **October 5, 2025**)
07. NVD (NIST) — **CVE-2025-61884** detail page (includes KEV dates)
08. Oracle — Security Alert for **CVE-2025-61882**
09. Oracle — Security Alert for **CVE-2025-61884**
10. Oracle — Critical Patch Update Advisory ( **October 2025**)
11. Maine Attorney General Data Breach Notifications — The Washington Post filing (consumer notice **November 12, 2025**, total affected **9,720**)
12. Maine Attorney General Data Breach Notifications — GlobalLogic filing (consumer notice **November 7, 2025**, total affected **10,471**)
13. Maine Attorney General Data Breach Notifications — Cox Enterprises filing (consumer notice **November 20, 2025**, total affected **9,479**)
14. Maine Attorney General Data Breach Notifications — LKQ filing (consumer notice **December 15, 2025**, total affected **9,070**)
15. Politico — Former Washington Post employee launches class action suit after data breach ( **December 5, 2025**)
16. SecurityWeek — Oracle says known vulnerabilities possibly exploited in extortion attacks ( **October 10, 2025**)
17. TechCrunch — Hackers are sending extortion emails to executives after claiming Oracle apps data breach ( **October 2, 2025**)
18. TechRepublic — Oracle extortion case cites demands up to **$50 million** ( **October 2, 2025**)
