{"id":7386,"date":"2025-10-03T10:04:30","date_gmt":"2025-10-03T10:04:30","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/03\/oracle-confirms-that-hackers-targeting-e-business-suite-data-with-extortion-emails\/"},"modified":"2025-10-03T10:04:30","modified_gmt":"2025-10-03T10:04:30","slug":"oracle-confirms-that-hackers-targeting-e-business-suite-data-with-extortion-emails","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/03\/oracle-confirms-that-hackers-targeting-e-business-suite-data-with-extortion-emails\/","title":{"rendered":"Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails"},"content":{"rendered":"<p>    Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Oracle Corporation has officially acknowledged that cybercriminals are targeting customers of its E-Business Suite (EBS) platform through sophisticated <a href=\"https:\/\/cybersecuritynews.com\/unc3944-hackers-evolves-from-sim-swap-to-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener\">extortion campaigns<\/a>.\u00a0<\/p>\n<p>The company\u2019s Chief Security Officer, Rob Duhart, confirmed that hackers have been exploiting previously identified vulnerabilities that were addressed in Oracle\u2019s July 2025 Critical Patch Update (CPU).\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEil7nHxfNfNv9nUB89YIPtBDga6-eOEUiXgEf48SfstHhdLvH9fWDsA0gBY24QcWtMQgQRyWsBbmPHHWGiArrFmAiLnIzdtlbuTKwXC2FRdPtethgnCes35VfLmvcpSpMg0RICeJESlhnws-h8Fz-KvXDCa2NKQxI7yNos7lycw_RpwGpjVUn_7T8nfZvZZ\/w640-h374\/Oracle%2520Security%2520Update.png?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>This latest security incident underscores the persistent threat landscape facing enterprise applications and highlights the critical importance of timely security patch deployment.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-oracle-e-business-suite-customers-targeted\">\n<strong>Oracle E-Business Suite<\/strong> <strong>Customers Targeted<\/strong><br \/>\n<\/h2>\n<p>Bloomberg <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2025-10-02\/cyber-group-extorting-executives-with-claims-of-stolen-data\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">stated that<\/a> the cybercriminal group, claiming affiliation with the notorious <a href=\"https:\/\/cybersecuritynews.com\/cl0p-ransomware-data-exfiltration-vulnerable\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cl0p ransomware<\/a> organization, has been conducting a highly coordinated attack campaign against Oracle E-Business Suite installations.\u00a0<\/p>\n<p>According to cybersecurity firm Halcyon, the threat actors have demonstrated sophisticated tactics, techniques, and procedures (TTPs) by compromising user email accounts and exploiting default password-reset functions to obtain valid credentials for internet-facing Oracle EBS portals.<\/p>\n<p>The attackers have provided victims with proof of compromise, including detailed screenshots and file tree structures demonstrating unauthorized access to sensitive corporate data.\u00a0<\/p>\n<p>In at least one documented case, the extortion demands reached as high as $50 million, representing one of the largest ransom demands observed in recent cybercriminal campaigns.\u00a0<\/p>\n<p>The threat actors began distributing extortion emails on or before September 29, 2025, using hundreds of compromised third-party email accounts to evade detection mechanisms.<\/p>\n<p>Oracle\u2019s E-Business Suite, which manages critical enterprise functions including financial management, <a href=\"https:\/\/cybersecuritynews.com\/supply-chain-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">supply chain operations<\/a>, and customer relationship management (CRM), has become an attractive target due to its extensive deployment across large organizations.\u00a0<\/p>\n<p>The vulnerability exploitation appears to leverage previously identified security flaws that were patched in <a href=\"https:\/\/cybersecuritynews.com\/oracle-critical-security-update-july2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">Oracle\u2019s July 2025 Critical Patch<\/a> Update, specifically addressing CVE identifiers related to authentication bypass and privilege escalation attacks.<\/p>\n<p>Genevieve Stark, head of cybercrime at Google Threat Intelligence Group, confirmed that the extortion emails contain contact details matching those listed on Cl0p\u2019s official dark web infrastructure.\u00a0<\/p>\n<p>The threat group\u2019s modus operandi includes characteristic grammatical errors and linguistic patterns consistent with previous Cl0p operations, including their infamous 2023 <a href=\"https:\/\/cybersecuritynews.com\/moveit-transfer-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">MOVEit campaign<\/a> that compromised over 3,000 organizations in the United States and 8,000 globally.<\/p>\n<p>Oracle has reiterated its strong recommendation for the immediate deployment of the latest Critical Patch Updates, emphasizing that organizations maintaining current security patch levels significantly reduce their attack surface.\u00a0<\/p>\n<p>The company\u2019s <a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujul2025.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">security advisory<\/a> specifically references the July 2025 CPU, which addressed multiple high-severity vulnerabilities with CVSS scores ranging from 7.5 to 9.8, including remote code execution (RCE) and <a href=\"https:\/\/cybersecuritynews.com\/tag\/sql-injection\/\" target=\"_blank\" rel=\"noreferrer noopener\">SQL injection<\/a> attack vectors.\u00a0<\/p>\n<p>Organizations experiencing similar extortion attempts are advised to contact Oracle Support immediately while implementing incident response procedures, including network segmentation and the preservation of forensic data.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-targeting-oracle-e-business-suite\/\">Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-targeting-oracle-e-business-suite\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails Oracle Corporation has officially acknowledged that cybercriminals are targeting customers of its E-Business Suite (EBS) platform through sophisticated extortion campaigns.\u00a0 The company\u2019s Chief Security Officer, Rob Duhart, confirmed that hackers have been exploiting previously identified vulnerabilities that were addressed in Oracle\u2019s July 2025 Critical [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63,131],"tags":[130],"class_list":["post-7386","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7386"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7386"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7386\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}