Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Google Warned Executives About Oracle EBS Extortion Emails. Later Analysis Found Real Data Theft

Attackers claiming Cl0p ties targeted executives with Oracle EBS extortion emails in 2025. Google later confirmed real exploitation and data theft in some customer environments, while Oracle issued emergency patches.
From TheFinanceBase Team7 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—the 2025 Oracle extortion campaign was real, but the first emails overstated what was known. Attackers claiming links to the Cl0p (also styled CL0P) extortion operation targeted executives and IT departments beginning September 29, 2025. Google initially said it could not verify every claim. Later Google Threat Intelligence Group and Mandiant found evidence that attackers had exploited customer-managed Oracle E-Business Suite (EBS) systems and stolen data from some organizations. Oracle issued emergency patches, but patching alone could not undo earlier access.

The incident was not evidence that Oracle Corporation, Oracle Cloud Infrastructure, or every Oracle customer had been breached. The confirmed reporting concerns particular Oracle EBS environments used by customers.

What happened

Oracle E-Business Suite is enterprise software for finance, accounting, payroll, human resources, procurement, manufacturing, logistics, and supply-chain operations. A compromise can therefore expose highly sensitive business and personal information, including payroll records, supplier files, contracts, financial data, and customer information.

In late September 2025, a Cl0p-claiming actor sent a high volume of emails to executives and technology departments. The messages alleged that data had been stolen from the recipients’ Oracle EBS systems. Some emails included file listings that appeared to come from real victim environments. The messages used contact addresses associated with the Cl0p leak site, including [email protected] and [email protected], and were sent from hundreds or potentially thousands of compromised third-party email accounts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google’s first public warning on October 2 said the allegations had not yet been definitively verified. Its subsequent technical investigation found that the emails followed months of intrusion activity, including successful exploitation and data theft at some organizations. That changed the incident from an unverified extortion story into a confirmed campaign with an uncertain number of victims and uncertain attribution for the individual operators.

Google later described dozens of known victims and expected more. Reuters reported Google’s assessment that more than 100 companies were likely affected, an evolving estimate rather than a final audited count.

Halcyon reported ransom demands in the seven- and eight-figure range, including one reported demand of $50 million. That figure was an observed demand, not a standard price or amount requested from every recipient.

Timeline of the Oracle EBS campaign

Date What investigators reported
July 10, 2025 Google/Mandiant identified suspicious activity involving Oracle EBS environments dating back to this period.
August 9, 2025 Google assessed that exploitation may have begun as early as this date, potentially involving a then-undisclosed vulnerability.
September 29, 2025 High-volume extortion emails began reaching executives and IT departments.
October 2, 2025 Google publicly warned about the emails and said it could not yet verify all breach claims.
October 4, 2025 Oracle issued emergency patching guidance for the vulnerability associated with the campaign.
October 9, 2025 Google/Mandiant published technical findings describing real exploitation and data theft from some victims.
October 11, 2025 Oracle released another update addressing CVE-2025-61884.

Google’s technical account is available at Google Cloud’s threat-intelligence analysis. Early reporting and Oracle patch coverage are also documented by ITPro and ITPro’s patch report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who was behind it?

The senders claimed affiliation with Cl0p, and Google identified links between the campaign’s contact addresses and the Cl0p data-leak site. That is not the same as proving that Cl0p’s core organization carried out every intrusion. Extortion brands are commonly used by affiliates, copycats, and loosely connected criminal groups.

The careful description is therefore “Cl0p-claiming,” “Cl0p-branded,” or “apparently linked to Cl0p.” Google initially said it could not establish either that the actors were definitively Cl0p or that every recipient’s alleged breach was genuine. Later evidence confirmed real compromises in at least part of the operation, but it did not resolve responsibility for every message or victim.

Was Oracle itself hacked?

No cited evidence establishes a breach of Oracle Corporation’s internal network. The reporting concerns attackers exploiting Oracle EBS installations belonging to customers. That distinction matters:

  • Oracle EBS customer environments: The systems implicated in the campaign.
  • Oracle Cloud Infrastructure: Not shown by the cited reporting to have been compromised in this campaign.
  • Oracle Fusion Cloud Applications: A separate cloud application environment, not automatically implicated by an EBS incident.
  • Oracle’s corporate systems: No evidence in the cited sources establishes that they were breached.

Receiving an email that mentions Oracle data also does not prove that the recipient runs an affected EBS deployment. Each organization has to verify its own environment and evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the intrusions worked

Google/Mandiant described a multi-stage operation rather than one universally proven attack path. The observed activity included:

  • Exploitation of Oracle EBS servers and requests directed at EBS components.
  • Java-based malware or implant activity.
  • Access to and exfiltration of data from affected environments.
  • Extortion messages sent through compromised third-party email accounts.

Using legitimate compromised sender accounts could make the messages appear credible and help them bypass spam controls. The exact sequence varied between victims, so the campaign should not be reduced to a single exploit or a single malware sample.

Which vulnerabilities were involved?

CVE-2025-61882 was central to Google’s discussion of the campaign, and Oracle’s October 4 emergency patch addressed it. However, Google/Mandiant observed multiple exploit chains and did not initially tie every intrusion to that CVE alone. Oracle issued a further update on October 11 for CVE-2025-61884. Google assessed that EBS servers updated through the October 11 release were likely no longer exposed to the known exploitation chains.

Google assessed that some exploitation may have started before a public fix was available, which is why reports referred to possible zero-day use. “Possible zero-day” does not mean CVE-2025-61882 explains every case, nor does a patch prove that a previously compromised server is clean. Organizations must check for earlier access, persistence, and exfiltration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How credible were the extortion emails?

What was known on October 2

Google had observed the messages but lacked enough evidence to validate all of the alleged breaches. Threat actors can copy a leak-site identity, send generic claims, or attach fabricated file lists. A recipient should not assume either authenticity or fraud from the email alone.

What later analysis established

Google/Mandiant found legitimate file listings tied to victim EBS environments, data dating to mid-August 2025, and evidence that data had actually been exfiltrated from some organizations. Those findings strongly support genuine compromises in part of the campaign. They do not prove that every listed organization was breached or that an attacker had unrestricted access to its entire enterprise.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What an organization receiving an email should do

  1. Preserve the message. Keep the original email, complete headers, attachments, and metadata. Do not click links or circulate the message broadly.
  2. Open an incident investigation. Treat the claim as unverified but serious. Compare any listed file names, paths, records, or screenshots with internal systems and data owners.
  3. Map the EBS deployment. Identify every EBS instance, hosting arrangement, supported version, and period in which an instance was reachable from the internet. Do not assume that a VPN alone prevented exploitation.
  4. Apply Oracle’s relevant updates. Follow Oracle’s October 2025 advisories for the supported EBS version, including fixes associated with CVE-2025-61882 and CVE-2025-61884. Confirm installation on each instance rather than relying on an approval ticket.
  5. Review historical logs. Examine web and application logs, EBS access records, authentication and password-reset events, Java process activity, outbound connections, unusually large exports, and creation or modification of administrator accounts from at least July through October 2025.
  6. Hunt for persistence. Check for unknown Java files, web shells, scheduled tasks, modified application objects, and unexpected processes. Compare hosts with a known-good baseline.
  7. Rotate secrets carefully. Prioritize EBS service accounts, privileged users, database credentials, API secrets, and credentials accessible from the EBS host. Coordinate the work with forensic preservation so remediation does not destroy evidence.
  8. Bring in specialist help when warranted. Use incident-response counsel and forensic specialists when there is evidence of privileged access, data theft, or complex regulatory exposure. Coordinate legal, insurance, communications, and technical decisions before contacting the extortion actor.
  9. Assess the data. Determine whether payroll, employee, customer, supplier, financial, trade-secret, or other regulated information was accessed.
  10. Handle notifications through counsel. Reporting and notification duties depend on the data, jurisdiction, sector rules, and contractual requirements; there is no single deadline that applies to every organization.

Questions the evidence cannot yet answer

  • The final number of victims remains unknown. “More than 100” was Google’s later estimate of likely affected companies, not a completed victim list.
  • It is not established that every recipient had a compromised EBS system.
  • The complete exploit chain for every environment, and the precise division of responsibility between Cl0p and possible affiliates, remain unclear.
  • The cited reporting does not establish that Oracle Cloud Infrastructure or Oracle’s corporate network was compromised.

A legitimate file listing can show that an attacker obtained some information; it cannot, by itself, establish access to every module or system in the enterprise. Likewise, a patched server can still contain evidence of earlier compromise or credentials that were stolen before patching.

Bottom line for Oracle customers

This was a genuine Oracle EBS exploitation and data-extortion campaign, not proof that “Oracle was hacked” across the board. The first warnings correctly treated the claims as unverified; later Google/Mandiant findings showed that real intrusions and theft had occurred. Organizations that received a message—or that operated an exposed EBS system during the relevant period—should patch, preserve evidence, investigate historical activity, rotate affected secrets, and determine what data was accessed before deciding how to respond or whether to engage the extortionist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources: ITPro initial warning; Google/Mandiant technical analysis; Reuters report on the initial campaign and ransom claims; Reuters report on Google’s later victim estimate; TechCrunch context.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.