Categories: Cyber Security News

Allianz UK Joins Expanding List of Clop’s Alleged Oracle E-Business Suite Victims

Allianz UK has become the latest major organization to fall victim to cybercriminals exploiting a critical Oracle E-Business Suite vulnerability.

The attackers gained access through the company’s EBS system, which manages personal lines business, including home, car, pet, and travel insurance products.

The UK subsidiary of the insurance giant confirmed the breach but declined to comment on potential extortion demands from the Clop criminal group.

Allianz UK did report the incident to the Information Commissioner’s Office, though the regulator has not publicly acknowledged the claim.

The company emphasized that this attack remains separate from a previous breach affecting Allianz Life, its American subsidiary.

That incident compromised data belonging to 1.4 million customers in July. The distinction underscores the widespread nature of the vulnerability affecting multiple enterprise systems across different regions.

Allianz UK now joins an expanding roster of victims, including the Washington Post, which confirmed a related attack earlier this week.

American Airlines’ subsidiary Envoy Air also disclosed its compromise last month, demonstrating Clop’s sustained targeting of major corporations through the same EBS exploit.

Security researchers at Google estimate that “dozens” of organizations have been affected by attacks exploiting CVE-2025-61882, which carries a critical 9.8 CVSS score.

Sponsored

Investigations suggest the exploitation campaign began as early as July, three months before any public detection, providing attackers with a significant head start.

“Large-scale zero-day campaigns like this are becoming a regular feature of cybercrime,” warned John Hultquist, chief analyst at Google Threat Intelligence Group.

Historical Clop campaigns have impacted hundreds of victims, though exact numbers remain unclear.

The group previously gained notoriety through the 2023 MOVEit MFT supply chain attack, which compromised over 95 million individuals and approximately 3,000 organizations.

The current Oracle EBS campaign demonstrates Clop’s continued sophistication and access to critical vulnerabilities targeting enterprise infrastructure.

CVE ID CVSS Score Affected Product Status Attack Vector
CVE-2025-61882 9.8 Oracle E-Business Suite (EBS) Actively Exploited Remote Code Execution

Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

The post Allianz UK Joins Expanding List of Clop’s Alleged Oracle E-Business Suite Victims appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

The Massive 77″ Panasonic Z85 4K OLED TV with Amazon Fire TV Drops to Just $1,399.99 Shipped

Here's a rare chance to pick up a massive, current generation, higher-end OLED TV at…

53 minutes ago

Total Wireless by Verizon Is Offering the New Apple iPhone 17e “On Us” With No Trade-In or Port-In Required

Apple recently unveiled its newest budget smartphone - the Apple iPhone 17e - on March…

53 minutes ago

Hackers Use Fake CleanMyMac Site to Deploy SHub Stealer and Hijack Crypto Wallets

A convincing fake website posing as the popular Mac utility CleanMyMac is actively pushing dangerous…

2 hours ago

BoryptGrab Stealer Spreads via Fake GitHub Repositories, Stealing Browser and Crypto Wallet Data

A new data-stealing malware called BoryptGrab has been quietly spreading across Windows systems through a…

2 hours ago

Apple smart home display rumors now point to a fall launch with iOS 27

The rumored "HomePod with a screen" we've heard so much about was reportedly lined up…

3 hours ago

The government shutdown is hitting airports — but not ICE

Department of Homeland Security. | Image: The Verge Chaos reigned at airports across the country…

3 hours ago

This website uses cookies.