logo

American Airlines subsidiary Envoy confirms Oracle data theft attack

ID: ce3e18cd-ca60-5030-b25c-d2574760ff16

STIX ID: report--ce3e18cd-ca60-5030-b25c-d2574760ff16

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-10-17

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

Envoy Air confirmed that data from its Oracle E-Business Suite was compromised and that the Clop extortion gang has listed American Airlines on its leak site; Clop claims the theft was part of an August campaign exploiting Oracle zero-day vulnerabilities (CVE-2025-61882 and CVE-2025-61884). The report notes limited business and contact data exposure, ties the activity to a broader Clop campaign affecting multiple organizations (including Harvard), and highlights Oracle patches and Clop's shift to zero-day exploitation for data theft and extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.