CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Clop extortion campaign targets Oracle E-Business Suite

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Executives at multiple companies received extortion emails claiming that sensitive data was stolen from their Oracle E-Business Suite systems. The campaign began in late September 2025 and is linked to the Clop ransomware gang. The emails were sent from compromised accounts, some previously associated with the FIN11 threat group. The emails contain contact addresses known to be listed on the Clop ransomware gang's data leak site. The extortion emails claim that sensitive data was stolen from Oracle E-Business Suite systems. The emails were sent from compromised accounts, some previously associated with the FIN11 threat group. The emails contain contact addresses known to be listed on the Clop ransomware gang's data leak site. Mandiant and GTIG are investigating the claims and recommend that organizations receiving these emails investigate their environments for unusual access or compromise in their Oracle E-Business Suite platforms.

Timeline

  1. 02.10.2025 06:13 1 articles · 2h ago

    Clop extortion emails claim theft of Oracle E-Business Suite data

    Executives at multiple companies received extortion emails claiming that sensitive data was stolen from their Oracle E-Business Suite systems. The campaign began in late September 2025 and is linked to the Clop ransomware gang. The emails were sent from compromised accounts, some previously associated with the FIN11 threat group. The emails contain contact addresses known to be listed on the Clop ransomware gang's data leak site.

    Show sources

Information Snippets