Cl0p Oracle E-Business Suite extortion wave
An extortion actor using the Cl0p brand exploited a zero-day in Oracle E-Business Suite (CVE-2025-61882) to steal data from customers' ERP environments, then sent mass extortion emails to executives from late September 2025.
- Victim
- Oracle E-Business Suite customers (Cl0p extortion wave)
From 29 September 2025, executives at organisations running Oracle E-Business Suite (EBS), Oracle's enterprise ERP platform for finance, HR, procurement and supply-chain functions, began receiving extortion emails from an actor claiming affiliation with the Cl0p extortion group. The emails claimed that sensitive business data had been stolen from the recipients' EBS environments and pointed to contact addresses already listed on Cl0p's data-leak site. On 2 October 2025, Oracle confirmed it was investigating the messages, and Google and Mandiant publicly reported the campaign.
What happened
The campaign follows Cl0p's now-familiar model: rather than encrypting systems, the actor quietly exfiltrates data and then threatens to publish it unless the victim pays, an extortion built on the fear of exposure rather than operational disruption. Early reporting cited seven- and eight-figure ransom demands, including one demand of $50 million.
Google Threat Intelligence Group linked the data theft to exploitation of a zero-day vulnerability in Oracle E-Business Suite tracked as CVE-2025-61882, a flaw allowing unauthenticated remote code execution. It observed suspicious activity as early as 10 July 2025 and confirmed zero-day exploitation from 9 August 2025, weeks before any extortion email was sent. Oracle released an emergency patch on 4 October 2025 and fixed a further EBS flaw, CVE-2025-61884, on 11 October.
Google did not formally attribute the activity to a tracked group. It noted that the post-exploitation tooling, including the in-memory Java loader GOLDVEIN.JAVA, resembles malware used by the suspected FIN11 cluster, while cautioning that the Cl0p brand and leak site are not used exclusively by FIN11.
Large companies named in August 2026 alongside Cl0p, such as Shell, Philips, General Electric and Fiserv, belong to a separate operation: Cl0p's PTC Windchill campaign, which exploited CVE-2026-12569 in PTC Windchill and FlexPLM rather than Oracle EBS.
Impact
- Executives at numerous Oracle EBS customer organisations received extortion emails; Google did not publish a victim count.
- The stolen material came from ERP systems of record, which hold financial, HR, procurement and supply-chain data.
- Organisations that patched only after the emails began may already have been compromised, given the weeks of exploitation that preceded the extortion wave.
Why it matters
The Oracle EBS wave echoes Cl0p's earlier mass-exploitation campaigns against managed file-transfer products such as MOVEit, GoAnywhere and Accellion: identify a single widely deployed enterprise product, exploit a zero-day at scale, and monetise through data-theft extortion rather than encryption. Targeting a core ERP platform shifts the exposure from file-transfer gateways to the systems of record that hold a company's financial, procurement and HR data. It also underlines the danger of long-dwell zero-day exploitation: the gap of more than two months between the first suspicious activity and the extortion emails means victims may have been compromised long before receiving any demand.
Timeline
Google Threat Intelligence Group observes the earliest suspicious activity against Oracle E-Business Suite servers linked to the campaign.
Earliest confirmed exploitation of the Oracle EBS zero-day later tracked as CVE-2025-61882.
A high-volume extortion email campaign begins, sent to executives at Oracle EBS customer organisations and claiming Cl0p affiliation.
Oracle confirms it is investigating the extortion emails; Google and Mandiant publicly report the campaign.
Oracle releases an emergency patch for CVE-2025-61882.
Google Threat Intelligence Group publishes its analysis of the zero-day exploitation and post-exploitation tooling.
Oracle patches a further E-Business Suite flaw, CVE-2025-61884.
Sources
- cybersecuritydive.comhttps://www.cybersecuritydive.com/news/oracle-investigating-extortion-emails-e-business-suite-customers/801932/
- bankinfosecurity.comhttps://www.bankinfosecurity.com/extortionists-claim-mass-oracle-e-business-suite-data-theft-a-29620
- cloud.google.comhttps://cloud.google.com/blog/topics/threat-intelligence/oracle-ebusiness-suite-zero-day-exploitation
- computerweekly.comhttps://www.computerweekly.com/news/366632397/Oracle-patches-E-Business-suite-targeted-by-Cl0p-ransomware