HomeNewsBusinessHackers extort executives after claiming Oracle apps breach

Hackers extort executives after claiming Oracle apps breach

A group of hackers claimed to have breached Oracle’s E-Business Suite, which runs core operations including financial, supply chain and customer relationship management

October 02, 2025 / 10:53 IST
Story continues below Advertisement
Oracle, Oracle news, Oracle latest news, Oracle apps, Oracle hacking, cyberattack
The hackers compromised user emails and abused the default password-reset function to gain valid credentials of internet-facing Oracle E-Business Suite portals, according to Halcyon

Executives and technology departments at large organizations are being extorted by a notorious ransomware group that claims to have stolen their data from a suite of popular Oracle Corp. applications.

A group of hackers claimed to have breached Oracle’s E-Business Suite, which runs core operations including financial, supply chain and customer relationship management. In one case, they demanded a ransom of up to $50 million, according to cybersecurity firm Halcyon, which is currently responding to the campaign. The group, which claims to be affiliated with a criminal outfit called Cl0p, has provided proof of compromise to victims including screenshots and file trees.

Story continues below Advertisement

“We have seen Cl0p demand huge seven- and eight-figure ransoms in the last few days,” said Cynthia Kaiser, vice president at Halcyon’s ransomware research center. “This group is notorious for stealthy, mass data theft that heightens their leverage in ransom negotiations.”

The group began sending extortion emails on or before Sept. 29, according to Genevieve Stark, head of cybercrime at Google Threat Intelligence Group. The emails were sent from hundreds of compromised third-party accounts and claimed the theft of data, she said.