Clop, a Russian-speaking cybercriminal group, has launched a widespread campaign exploiting a critical vulnerability in Oracle E-Business Suite (EBS), targeting hundreds of organizations globally. Allianz UK confirmed that it was among the victims, with the attackers compromising data belonging to 80 current and 670 former customers, though no impact was reported for its subsidiary Liverpool Victoria (LV). The attack vector was traced to Oracle EBS used in Allianz UK's personal lines business, and the company reported the incident to the Information Commissioner's Office. Other notable victims include the Washington Post and Envoy Air, with researchers estimating that dozens of organizations may have been affected since July, exploiting CVE-2025-61882.
Clop's campaign is characterized by data exfiltration and extortion rather than traditional ransomware, with the group threatening to leak stolen data unless contacted by victims within a set deadline. Logitech was also named as a target, though the company has not confirmed a breach. The campaign's scale is significant, with at least 835 documented victims attributed to Clop since 2019, and the group has previously exploited vulnerabilities in other file-transfer platforms such as MOVEit and Fortra GoAnywhere. The Oracle EBS vulnerability was first detected in July, with Oracle releasing an initial patch in October that proved insufficient, necessitating a second critical update and leaving many organizations exposed for several days.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
Logitech confirmed a data breach attributed to exploitation of a zero-day in a third-party platform reportedly involving Oracle E-Business Suite. The company said limited employee, consumer, customer, and supplier data was likely exfiltrated, but not highly sensitive data such as national ID or credit card numbers.
Reporting on November 13-14 indicated that The Washington Post was among the organizations impacted in Clop's Oracle EBS campaign, with nearly 10,000 people affected. The disclosure added another major victim to the growing list tied to CVE-2025-61882.
GlobalLogic disclosed that a breach tied to the Oracle EBS zero-day exposed sensitive HR data for nearly 10,500 current and former employees. The company acknowledged the theft as part of the wider Clop campaign targeting Oracle customers.
Allianz UK confirmed it was impacted by Clop's exploitation of Oracle E-Business Suite after claims involving Liverpool Victoria. The insurer said only Allianz UK customer data was affected, impacting 80 current and 670 former customers, and reported the matter to the UK ICO.
Oracle released a security patch for the Oracle E-Business Suite zero-day CVE-2025-61882 after months of exploitation. Affected organizations later reported applying the fix as part of their response.
GlobalLogic detected the breach in October 2025 and began notifying authorities, engaging third-party investigators, and applying Oracle's patches. The company later linked the incident to Clop's wider Oracle customer attack spree.
GlobalLogic said attackers accessed and stole sensitive HR data belonging to more than 10,000 current and former employees during a compromise window running from July 10 to August 20, 2025. Exposed data included personal identifiers, contact details, and financial information.
A broader Clop extortion campaign targeting Oracle E-Business Suite began as early as July 2025, according to reporting and Google researchers. The activity was tied to CVE-2025-61882 and is believed to have affected dozens of organizations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
12 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcezendata.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.