Categories: Cyber Security News

Oracle Confirms Targeted Attacks on E-Business Suite Data via Extortion Emails

Oracle has confirmed that a group of hackers stole data from its E‑Business Suite (EBS) applications and is leveraging the information in a wave of extortion emails targeting large enterprises.

The company says attackers exploited vulnerabilities addressed in the July 2025 Critical Patch Update (CPU) and urged all customers to apply the latest patches immediately to prevent further intrusions.

Executives and IT leaders at multiple organizations have received emails claiming their EBS data was copied, with ransom demands reportedly reaching up to 50 million dollars.

Victims have been shown screenshots, file indexes, and sample records as proof to pressure payment attempts.

Halcyon incident responders say the threat actors are presenting themselves as affiliated with the Cl0p ransomware operation, a group known for stealthy mass data theft and high-dollar extortion.

Cl0p previously exploited MOVEit file-transfer flaws to compromise hundreds of organizations, including major brands such as Shell, British Airways, and the BBC.

Security researchers note the extortion notes in this campaign feature the same poor English and grammar historically seen in Cl0p communications.

Google’s Threat Intelligence Group added that at least one email address used in these notes was previously linked to a Cl0p affiliate.

Oracle’s investigation is ongoing, and the company has not publicly confirmed the precise intrusion vector.

Details of the Campaign

The extortion emails began on or before September 29, sent from hundreds of compromised third‑party accounts to evade filtering and increase credibility.

At least one affected organization has publicly acknowledged EBS data exfiltration.

While some reports suggest the actors abused default password‑reset functions on internet‑exposed EBS portals, others believe the breach stems from exploitation of an EBS flaw remediated in the July CPU.

Oracle advises all EBS customers to verify that the July 2025 CPU has been applied across every instance, especially internet‑facing environments and non‑production clones often overlooked in patch cycles.

Immediate defensive actions include reviewing access logs for anomalous password‑reset activity, monitoring third‑party and shared mailboxes for compromise, enforcing strong multi‑factor authentication for all EBS access, and restricting administrative functions to trusted networks.

Organizations should also validate system integrity with automated scans, ensure offline, tested backups, and tighten email authentication controls (SPF, DKIM, DMARC) to reduce the impact of account hijacking used in this campaign.

Oracle is coordinating with law enforcement and cybersecurity partners and emphasizes that applying the July 2025 CPU remains the most critical step to mitigate these extortion threats.

CVE Table (related to July 2025 CPU for Oracle E‑Business Suite)

  • Affected Products: Oracle E‑Business Suite (various modules)
  • Impact: Data exfiltration risk via exploited application/server vulnerabilities
  • Exploit Prerequisites: Internet‑exposed EBS endpoints, outdated CPU level, weak MFA or misconfigured password‑reset workflows
  • CVSS 3.1: High to Critical (organization‑specific per module and patch advisory)
  • Notes: Oracle states the exploited issues were fixed in the July 2025 CPU; customers must verify full deployment across all instances and environments

Find this Story Interesting! Follow us on Google NewsLinkedIn and X to Get More Instant Updates

The post Oracle Confirms Targeted Attacks on E-Business Suite Data via Extortion Emails appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Disguise, Creative Technology Power Eurovision 2026 With Next-Gen Visual Tech

Disguise is partnering with Creative Technology to provide the visual playback backbone for the Eurovision…

30 minutes ago

The Weather Company Debuts Max On Demand To Scale Cloud-First Weather Production

The Weather Company introduced Max On Demand, a cloud-native extension of its Max Cloud platform…

30 minutes ago

Nightspeed Sports Graphics Package Expands From KRON San Francisco To WPIX New York

Motion designer Jon Berry of jonberrydesign has expanded Nightspeed, a custom motion graphics package created…

30 minutes ago

IAB Releases Campaign Data Standards 1.0 For Public Comment

The post IAB Releases Campaign Data Standards 1.0 For Public Comment appeared first on TV…

30 minutes ago

Stop The False Choice: 5G Broadcast Can Ride Inside ATSC 3.0, And We Can Deploy Now

The post Stop The False Choice: 5G Broadcast Can Ride Inside ATSC 3.0, And We…

30 minutes ago

Canon Rolls Out EOS R6 V & RF20-50mm Power-Zoom Lens Aimed At Video Creators

Canon U.S.A. is expanding its EOS V-series with the EOS R6 V full-frame body and…

30 minutes ago

This website uses cookies.