Barts Health NHS Trust has confirmed that the Cl0p ransomware group gained unauthorized access to one of its invoice databases by exploiting a vulnerability in Oracle E-Business Suite, resulting in the theft of sensitive data. The breach exposed names and addresses of patients billed for care, records of former staff with unresolved salary issues, and payment details for suppliers, though most supplier information was already public. Files related to accounting services for Barking, Havering, and Redbridge University Hospitals NHS Trust since April 2024 were also compromised. The attack occurred in August but was only discovered in November when Cl0p leaked 241 GB of data on its dark web site. Oracle has since patched the exploited flaw, and Barts Health NHS Trust has reported the incident to relevant authorities and is seeking a High Court order to prevent further dissemination of the stolen data.
The Cl0p ransomware group has been actively exploiting the Oracle EBS vulnerability, tracked as CVE-2025-61882, as a zero-day in a broader campaign targeting organizations worldwide. Barts Health NHS Trust, which operates five major hospitals in London, is among several high-profile victims, with the breach highlighting the ongoing threat posed by ransomware actors to healthcare providers. Clinical systems and patient medical records were reportedly not affected, and the risk of data exposure is currently limited to those with access to the dark web leak. Barts Health has advised affected individuals to review any invoices they received to determine if their data was involved in the breach.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
In early December 2025, Barts Health publicly confirmed that Clop was behind the breach of its Oracle E-Business Suite environment and that 241 GB of invoice-related data had been exposed. The trust said the incident affected administrative and accounting data, including some files related to Barking, Havering, and Redbridge University Hospitals NHS Trust, but not patient records or clinical systems.
By early December 2025, Barts Health had sought a High Court injunction to prevent further publication or sharing of the stolen data already posted by Clop. The legal action aimed to suppress dissemination of patient, staff, and supplier information, though reports noted such orders may have limited practical effect on the gang.
After confirming the incident, Barts Health notified relevant authorities including the ICO, National Cyber Security Centre, and Metropolitan Police, and coordinated with NHS England on the response. The trust also warned affected individuals to review invoices and stay alert for phishing, fraud, and social engineering attempts.
In November 2025, Barts Health discovered the breach when exfiltrated files were posted on Clop's dark web leak site. Reports say the leak included invoices and other financial records containing names, addresses, and payment-related information.
Oracle patched the exploited Oracle E-Business Suite zero-day on October 4, 2025, after Clop had already used it in a wider campaign against multiple organizations. The fix came after months of reported exploitation dating back to August 2024 in the broader campaign.
In August 2025, the Clop ransomware group exploited Oracle E-Business Suite vulnerability CVE-2025-61882 to access Barts Health NHS Trust's invoice database. The attackers stole administrative data including patient, former staff, and supplier information, while core IT and clinical systems were not affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
upguard-staging.webflow.io
Open sourcego.theregister.com
Open sourcesecurityaffairs.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcehackread.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.