logo

Clop extortion emails claim theft of Oracle E-Business Suite data

ID: 3b027016-d95d-5e0d-b5b3-2a8dbded00ec

STIX ID: report--3b027016-d95d-5e0d-b5b3-2a8dbded00ec

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-10-02

Date Updated: 2026-07-17

Author: Lawrence Abrams

...
...

**Executive summary:** Mandiant, Google, and GTIG are tracking a high-volume extortion campaign where hundreds of compromised email accounts are sending messages claiming sensitive data was stolen from Oracle E-Business Suite; the messages are linked to the Clop/FIN11 extortion operation, and Oracle indicates the actors likely used vulnerabilities addressed in the July 2025 Critical Patch Update, though confirmed data theft has not been established.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.