Cl0p Oracle E-Business Suite extortion wave
An extortion actor using the Cl0p brand exploited a zero-day in Oracle E-Business Suite (CVE-2025-61882) to steal data from customers' ERP environments, then sent mass extortion emails to executives from late September 2025.
- Victim
- Oracle E-Business Suite customers (Cl0p extortion wave)