<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Cl0p Ransomware Gang Names 29 Victims in Oracle EBS Hack Campaign

Cl0p ransomware hits 29 firms, leaks data; targets include Harvard, Envoy Air, and more. Exploited Oracle EBS flaws CVE-2025-61882/84.
Content Team

The Cl0p ransomware group has publicly named 29 organizations allegedly hit in a cyberattack targeting Oracle's E-Business Suite customers. The campaign, linked to threat actor FIN11, involved extortion emails sent to executives in late September.

Confirmed victims include Harvard University, South Africa's Wits University, American Airlines subsidiary Envoy Air, and The Washington Post. Major corporations like Schneider Electric, Emerson, Logitech, and Cox Enterprises appear on the list but haven't confirmed breaches.

The hackers leaked data from 18 victims, sometimes releasing terabytes of files. The attacks likely exploited Oracle EBS vulnerabilities CVE-2025-61882 and CVE-2025-61884, which allow remote access without authentication. Most targeted organizations remain silent while conducting investigations.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo