Oracle E-Business Suite CVE-2025-61882 exploitation, extortion, and breach fallout
Case score 71
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 71
- Main story score
- 65
- Related evidence lift
- +6 / 20
- Contributing updates
- 2
- Context updates
- 2
- Exploitation Wave Defines the ongoing Oracle EBS exploitation wave, timing, and disclosed victim fallout. main
- Vulnerability Defines CVE-2025-61882, affected versions, exploitation status, and concrete university breach fallout. main
- Security Patch Release Anchors the emergency fix and KEV response for CVE-2025-61884. context
- Security Patch Release Anchors the emergency fix and mitigation state for CVE-2025-61882. context
-
Old: Oracle E-Business Suite exploitation and extortion around CVE-2025-61882New: Oracle E-Business Suite CVE-2025-61882 exploitation, extortion, and breach falloutWhy old title changed: The previous title is too generic now that the scope includes confirmed breach fallout at universities alongside the exploitation and extortion activity.The new title keeps CVE-2025-61882 central while better reflecting the reader-facing story: active exploitation, extortion pressure, and confirmed downstream breach disclosures.
Overview
Latest development Open development history Harvard University confirmed as Oracle EBS campaign victim Harvard University was listed on the Cl0p data leak website on October 12, and the cybercriminals later published a link to data allegedly stolen from Harvard. Harvard confirmed it was targeted in the Oracle EBS campaign and said the impact appears limited to a small administrative unit, while GTIG and Mandiant said dozens of organizations have been targeted.
-
GTIG links Oracle EBS extortion campaign to Clop/FIN11
Google Threat Intelligence Group and Mandiant said Clop/FIN11 likely began targeting Oracle E-Business Suite instances as early as August 9, 2025 and later used extortion emails sent since September 29 to executives at several organizations, including messages tied to [email protected] and [email protected]. The researchers said the campaign followed months of intrusion activity, that CVE-2025-61882 exploitation began before patches were available, and that the threat actor had already exfiltrated a significant amount of Oracle EBS data.
-
Oracle discloses CVE-2025-61882 and publishes leaked IOC
Oracle discloses CVE-2025-61882, lists the leaked proof-of-concept as an IOC, and says the separate /OA_HTML/SyncServlet exploit path was fixed with mod_security rules and by stubbing out the SYNCSERVLET class.
-
Clop Oracle E-Business Suite extortion campaign
The campaign began its extortion phase when **Oracle E-Business Suite** ransom emails started reaching **multiple companies**. The opening demand centered on alleged stolen files and a threat to leak the data unless payment was made.
-
First known Oracle E-Business Suite exploitation on August 9, 2025
CrowdStrike identified the first known exploitation of CVE-2025-61882 in Oracle E-Business Suite on August 9, 2025, marking the start of the abuse pattern tied to Graceful Spider (aka Cl0p). The flaw is a critical unauthenticated remote code execution vulnerability in exposed Oracle EBS environments.