Oracle has confirmed that its customers are being targeted by data-stealing extortionists who are demanding ransoms in exchange for not leaking stolen data. The attackers are specifically focusing on organizations using Oracle E-Business Suite (EBS), with multiple cybersecurity firms reporting that executives at these organizations have received ransom emails demanding up to $50 million. Oracle has stated that, based on its ongoing investigation, there is no evidence that a zero-day vulnerability is being exploited in these attacks. Instead, the attackers appear to be leveraging previously identified vulnerabilities that were addressed in Oracle's July 2025 critical patch update. Of the 309 security patches issued in that update, nine were for Oracle EBS, with three of those vulnerabilities being remotely exploitable without authentication. The attackers are believed to be gaining access through internet-facing Oracle EBS portals, particularly by targeting local accounts that lack multifactor authentication (MFA), thereby bypassing enterprise single sign-on controls. Cybersecurity firm Halcyon highlighted that the absence of MFA on these accounts is a key factor enabling the attackers to compromise systems. Oracle has strongly reiterated its recommendation that all customers apply the latest critical patch updates to mitigate these risks. The extortion campaign has caused significant concern among Oracle EBS users, as the attackers claim to have accessed sensitive data and are threatening to leak it unless their demands are met. The campaign underscores the importance of timely patch management and the implementation of robust authentication controls, especially for systems exposed to the internet. Security experts warn that organizations failing to update their Oracle EBS installations remain at heightened risk of compromise. The incident has also prompted renewed calls for organizations to review their security posture, particularly regarding privileged account management and the enforcement of MFA. While Oracle continues to investigate the full scope of the campaign, the company maintains that customers who have applied the July 2025 patches are protected against the vulnerabilities being exploited. The situation highlights the ongoing threat posed by extortion-focused cybercriminals and the critical need for organizations to maintain up-to-date security measures. The campaign has also drawn attention to the broader issue of patch adoption lag, as many organizations continue to use outdated software versions despite available fixes. Oracle's response has included direct communication with affected customers and public advisories emphasizing the urgency of patching. The extortion emails and the technical details of the attack have been corroborated by multiple cybersecurity research firms, lending credibility to the reported tactics. The incident serves as a stark reminder of the evolving tactics of cyber extortionists and the persistent risks facing organizations that delay critical security updates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Oracle stated that it had found no evidence that customer extortion activity was linked to the exploitation of any zero-day vulnerabilities. The available references indicate this was the key disclosed development in the story.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.