Clop extortion emails claim theft of Oracle E-Business Suite data
ID: 3b027016-d95d-5e0d-b5b3-2a8dbded00ec
STIX ID: report--3b027016-d95d-5e0d-b5b3-2a8dbded00ec
Feed Name: Bleeping Computer
Threat Score
**Executive summary:** Mandiant, Google, and GTIG are tracking a high-volume extortion campaign where hundreds of compromised email accounts are sending messages claiming sensitive data was stolen from Oracle E-Business Suite; the messages are linked to the Clop/FIN11 extortion operation, and Oracle indicates the actors likely used vulnerabilities addressed in the July 2025 Critical Patch Update, though confirmed data theft has not been established.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
