A widespread extortion campaign has targeted executives at multiple organizations using Oracle's E-Business Suite, with attackers claiming to have stolen sensitive data from these systems. The campaign, which began on or before September 29, 2025, involves a high volume of emails sent from hundreds of compromised third-party accounts. These emails demand extortion payments and provide contact information that matches addresses listed on the Clop ransomware group's data leak site, suggesting a possible connection to the notorious threat actor. Security researchers from Mandiant and Google Threat Intelligence Group (GTIG) are actively investigating the claims, but as of now, there is no independent verification that any data has actually been stolen from Oracle E-Business Suite environments. The emails are highly targeted, reaching company executives and leveraging previously compromised email accounts, some of which have been associated with FIN11, another financially motivated threat group known for ransomware and extortion activities. The tactics used in this campaign closely resemble those previously employed by Clop, including the use of compromised accounts and public leak site contact details, but the group has not publicly claimed responsibility on its leak sites. Oracle has not responded to requests for comment, and there is no confirmation of any zero-day vulnerabilities being exploited in Oracle E-Business Suite as part of this campaign. Researchers emphasize that the credibility of the attackers' claims remains unproven, and organizations are urged to investigate their Oracle environments for signs of compromise or unusual access. The campaign's scale and sophistication highlight the ongoing threat posed by ransomware and extortion groups targeting enterprise software platforms. The incident has raised concerns among Oracle customers, many of whom are now conducting internal investigations to assess potential exposure. The use of hundreds of compromised accounts to distribute the extortion emails demonstrates the attackers' ability to orchestrate large-scale, coordinated campaigns. The incident also underscores the importance of monitoring for suspicious activity in critical business applications and maintaining robust incident response procedures. While the Clop group has a history of exploiting file-transfer services for mass data theft, such as the MOVEit breach in 2023, it remains unclear whether this Oracle campaign represents a similar level of compromise. Security experts continue to monitor the situation and advise vigilance among organizations using Oracle E-Business Suite. The lack of public confirmation from Clop and Oracle leaves many questions unanswered, but the campaign serves as a reminder of the persistent threat landscape facing enterprise IT environments. Organizations are encouraged to report any related incidents to law enforcement and share threat intelligence with trusted partners to help contain the potential impact.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Reporting identified Harvard University and Envoy Airlines as organizations allegedly breached in the Oracle E-Business Suite campaign. The disclosure added named victims to the incident beyond earlier generic reports of targeted customers.
Oracle said the activity was tied to flaws already addressed in its July 2025 Critical Patch Update rather than a new zero-day. The company advised customers to apply the July patches and stated it saw no evidence of zero-day exploitation in the extortion campaign.
Oracle acknowledged that some E-Business Suite customers had received extortion emails claiming compromise. The company said it was investigating with security partners and urged affected customers to seek support.
By October 3, reporting indicated that at least one targeted company had confirmed data theft connected to the campaign. This marked the first reported victim-side confirmation beyond the attackers' unverified claims.
Security reporting said the attackers were demanding seven- and eight-figure payments, with some outlets citing demands as high as $50 million. The extortion messages allegedly included screenshots and file trees as proof, though that evidence had not been independently verified.
Google Mandiant and Google Threat Intelligence Group began tracking the campaign as attackers used Clop-linked contact details and at least one sender account associated with FIN11. Investigators said attribution and the claimed data theft were not yet confirmed.
A mass extortion campaign targeting executives at organizations using Oracle E-Business Suite began in late September 2025, with reporting placing the start on or before September 29. The emails were sent from hundreds of compromised accounts and claimed sensitive Oracle EBS data had been stolen.
Oracle's July 2025 Critical Patch Update fixed nine Oracle E-Business Suite vulnerabilities, including three remotely exploitable flaws that did not require credentials. Later reporting tied the extortion activity to customers that had not applied these updates.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
27 references tracked. Mallory keeps watching after this page renders.
linkedin.com
Open sourcecpomagazine.com
Open sourcecomputerweekly.com
Open sourcecybereason.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.