Tech Souls, Connected.

Hackers Claim Oracle Breach, Demand $50M in Ransom From Victims

A ransomware-linked group is targeting major organizations with extortion emails after allegedly breaching Oracle’s enterprise apps — though Google says the claims remain unverified.


Extortion Campaign Targets Executives at Major Firms

A financially motivated hacking group, linked to the notorious Clop ransomware gang, is targeting executives at major companies with extortion emails — claiming to have stolen sensitive data from Oracle’s E-Business Suite (EBS).

  • The emails began circulating around September 29, according to Google, which is actively tracking the campaign.
  • Messages were sent from hundreds of compromised email accounts, including some tied to known cybercrime actors.

Genevieve Stark, Google’s head of cybercrime analysis, said the claims have not yet been verified, but the scale of the campaign and its ties to previous Clop attacks are raising concerns.


Mandiant Connects Campaign to Clop’s Leak Infrastructure

Charles Carmakal, CTO at Google-owned Mandiant, confirmed that many of the emails include contact details found on Clop’s data leak site — a known tool for pressuring victims into paying to avoid public data exposure.

  • This suggests the group may be using the threat of public disclosure as leverage.
  • The hackers are reportedly demanding multi-million-dollar ransoms, with one case reaching $50 million, according to Bloomberg.

Oracle’s E-Business Suite in the Spotlight

At the center of the campaign is Oracle’s E-Business Suite, a widely used enterprise software platform that handles HR, financials, supply chain, and customer data for thousands of global companies.

  • Hackers reportedly exploited the default password-reset function in exposed EBS web portals.
  • They gained access using compromised user credentials, allowing them to harvest sensitive corporate data.
  • This attack vector suggests the use of zero-day vulnerabilities or misconfigurations — a tactic Clop has used before to breach multiple organizations simultaneously.

Oracle has not commented on the breach claims. The company’s EBS software is used by governments, corporations, and global enterprises, amplifying the risk if the compromise is real.


A Familiar Tactic from a Prolific Adversary

Clop is one of the most active ransomware groups operating today, responsible for breaches of hundreds of organizations via high-profile zero-day exploits.

  • Past attacks include MOVEit, GoAnywhere, and Accellion — all exploited to extract sensitive data at scale.
  • The group’s strategy often relies on stealthy infiltration, followed by coordinated extortion and media pressure.

In this latest campaign, attackers appear to be bypassing encryption entirely by targeting unencrypted enterprise records stored in Oracle systems.


Industry Response and Ongoing Investigation

Cybersecurity firm Halcyon is reportedly working with at least one victim in this campaign, but has not publicly confirmed technical details.

  • Google and Mandiant are continuing to investigate the attack.
  • Security teams at affected companies are being urged to:
    • Audit external access to Oracle EBS portals
    • Disable or harden password reset functionality
    • Rotate credentials and investigate unauthorized access logs

With ransom demands reaching tens of millions, companies could be pressured to pay quickly if their leadership or employee data is at stake.

Share this article
Shareable URL
Prev Post

OpenAI’s $6.6B Share Sale: Liquidity for Employees, Pressure for Everyone

Next Post

AI Copilots Dominate, But Full Agents Are Coming, a16z Finds

Read next