Oracle customers being bombarded with emails claiming widespread data theft
ID: 189e65ae-9902-590e-8ff5-f4853057a5f1
STIX ID: report--189e65ae-9902-590e-8ff5-f4853057a5f1
Feed Name: CyberScoop
Researchers observed a high-volume extortion email campaign targeting Oracle E-Business Suite customers, with messages claiming data theft and using contact addresses tied to the Clop data leak site. Oracle acknowledged customers received extortion emails and noted the potential use of vulnerabilities addressed in its July 2025 critical patch update; investigators have not yet confirmed whether data was exfiltrated or which vulnerabilities were exploited. The emails originate from hundreds of compromised third-party accounts and pressure victims to negotiate, and while tactics align with Clop, attribution and successful breaches remain unverified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
