American Airlines subsidiary Envoy confirms Oracle data theft attack
ID: ce3e18cd-ca60-5030-b25c-d2574760ff16
STIX ID: report--ce3e18cd-ca60-5030-b25c-d2574760ff16
Feed Name: Bleeping Computer
Envoy Air confirmed that data from its Oracle E-Business Suite was compromised and that the Clop extortion gang has listed American Airlines on its leak site; Clop claims the theft was part of an August campaign exploiting Oracle zero-day vulnerabilities (CVE-2025-61882 and CVE-2025-61884). The report notes limited business and contact data exposure, ties the activity to a broader Clop campaign affecting multiple organizations (including Harvard), and highlights Oracle patches and Clop's shift to zero-day exploitation for data theft and extortion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
