Bimbo Bakeries USA confirmed that attackers stole employee information from an Oracle E-Business Suite environment operated by a third-party vendor. The company identified unauthorized file acquisition on December 6, 2025, and determined on August 19, 2026, that a stolen file contained employees’ names and Social Security numbers; it has not disclosed the number of people affected.
The intrusion aligns with the campaign exploiting CVE-2025-61882, a critical unauthenticated remote-code-execution vulnerability in Oracle EBS that has been linked by researchers to the Clop extortion group, although Bimbo has not attributed the incident to Clop or confirmed an extortion demand. Bimbo said it applied Oracle’s emergency patches, is reassessing vendor relationships, and is providing 12 months of credit monitoring and fraud-assistance services to affected individuals.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
Bimbo Bakeries USA's breach-notification letter was filed with the California Attorney General's Office.
Bimbo Bakeries USA issued a breach-notification letter describing the Oracle EBS incident and offered affected people 12 months of single-bureau credit monitoring and fraud assistance through Cyberscout.
Bimbo Bakeries USA confirmed that one of the files taken in the incident contained individuals' names and Social Security numbers.
Bimbo Bakeries USA determined that attackers had acquired files stored on an Oracle E-Business Suite platform used by a third-party vendor.
Oracle issued an emergency patch for CVE-2025-61882, which affects the BI Publisher Integration component of Oracle EBS Concurrent Processing.
Mandiant traced exploitation of CVE-2025-61882, an unauthenticated remote-code-execution flaw in Oracle E-Business Suite, to August 2025.
After learning of the Oracle EBS vulnerability, Bimbo Bakeries USA applied Oracle's emergency patches and initiated a forensic investigation. The company also said it was reassessing its vendor relationships.
CISA added CVE-2025-61882 to its Known Exploited Vulnerabilities catalog after Oracle disclosed the vulnerability.
Researchers attributed the broader Oracle EBS exploitation and extortion campaign, which affected numerous customers including Harvard University and The Washington Post, to the Clop ransomware and extortion group. Bimbo Bakeries USA has not publicly attributed its own breach to Clop.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.