logo

Oracle Extortion Case: $50M Demand From ‘Notorious’ Hacking Group

ID: 9ca89247-dfd1-59cc-916f-fb217ca0574a

STIX ID: report--9ca89247-dfd1-59cc-916f-fb217ca0574a

Feed Name: TechRepublic Security

Threat Score
78/100

Date Published: 2025-10-02

Date Updated: 2026-04-23

Author: J.R. Johnivan

...
...

A campaign attributed to the Cl0p ransomware group compromised Oracle E-Business Suite access—apparently via abused email accounts and password-reset flows—and began extorting executives at multiple large organizations with ransom demands (reported up to $50M) by sending mass emails containing screenshots and file-tree evidence of stolen data; the report notes the group's shift from zero-day exploitation to credential-based phishing and references CISA guidance for mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.