Clop gang exploited an Oracle E-Business Suite vulnerability to compromise Allianz UK customer data, affecting 80 current and 670 former customers while LV systems remained unaffected.
Clop raid on Oracle EBS started months ago, say researchers
Clop exploited multiple Oracle E-Business Suite vulnerabilities since August 2025, stole data, sent extortion demands, and public proof-of-concept exploit code now enables widespread attacks.
Emergency patch for vulnerability in Oracle E-Business Suite
Critical Oracle E-Business Suite vulnerability CVE-2025-61884 allows unauthenticated attackers to disclose sensitive data across EBS versions 12.2.3–12.2.14; urgent patching recommended.
Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks
Attackers exploited Oracle E-Business Suite, including CVE-2025-61882, to deploy malware such as GoldVein.Java and deliver second-stage payloads for extortion.
Cl0p-linked actors actively exploit a critical Oracle E-Business Suite zero-day for large-scale data theft while stealthy groups use compromised WordPress sites to deliver information-stealers.
Update on the emerging CL0P extortion campaign targeting Oracle E-Business Suite - DataBreaches.Net
CL0P exploited CVE-2025-61882 to exfiltrate large volumes of Oracle E-Business Suite data; apply Oracle patches and investigate for historical compromise.