The Clop ransomware group exploited a zero-day vulnerability in Oracle E-Business Suite to gain unauthorized access to the Washington Post's internal systems, resulting in the theft of sensitive personal and financial data belonging to nearly 10,000 current and former employees and contractors. The attackers accessed the environment between July 10 and August 22, 2025, and subsequently attempted to extort the company in late September after contacting the Post to claim responsibility for the breach. The compromised data included names, bank account numbers, routing numbers, and Social Security numbers, and the breach was confirmed after an internal investigation prompted by the extortion attempt.
The Washington Post is one of several major organizations targeted in this campaign, with other confirmed victims including Envoy Air and GlobalLogic. Oracle has since disclosed the vulnerability, now tracked as CVE-2025-61882 and CVE-2025-61884, and released patches to address the issue. The incident highlights the risks posed by zero-day vulnerabilities in widely used enterprise software and the increasing trend of ransomware groups leveraging such flaws for data theft and extortion campaigns against high-profile targets.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
The Washington Post publicly confirmed that data on nearly 10,000 employees, former employees, and contractors was stolen from its Oracle environment. The organization said it worked with external experts to investigate and offered affected individuals 12 months of identity protection services.
The UK's National Health Service confirmed it was aware of being named on Clop's cybercriminal site and said no data had been leaked so far. The statement publicly identified the NHS as one of the organizations caught up in the Oracle exploitation wave.
By early November 2025, Clop's data-leak site listed almost 30 alleged victims from the Oracle E-Business Suite campaign, including organizations such as the UK's NHS, Envoy Air, GlobalLogic, and Harvard University. This marked a broader public expansion of the victim list beyond initially disclosed cases.
Oracle released a patch on October 4, 2025 for a zero-day vulnerability in Oracle E-Business Suite that had been exploited in the campaign. Security firms later said Clop used multiple vulnerabilities in the attacks.
After the intrusions, victim organizations received extortion emails demanding payment and threatening to leak stolen data. Reporting indicates Oracle learned of the campaign through these extortion messages, with ransom demands reaching as high as $50 million.
Between July 10 and August 22, 2025, attackers exfiltrated personal and financial data from The Washington Post affecting nearly 10,000 current and former employees and contractors. Stolen data included names, bank account and routing numbers, and Social Security numbers.
Threat actors later linked to the Clop extortion group gained access to The Washington Post's Oracle E-Business Suite environment on July 10, 2025. The intrusion was part of a broader campaign targeting Oracle E-Business Suite customers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.