Oracle EBS Extortion Campaign Claims $50M Demand
Oracle EBS Extortion Campaign Claims $50M Demand

Oracle EBS Extortion Campaign Claims $50M Demand

News summary

Google’s Threat Analysis Group and Mandiant warn of a high‑volume extortion email campaign that began on or around Sept. 29, 2025, in which attackers claim to have stolen sensitive data from Oracle E‑Business Suite (EBS) instances. The campaign used hundreds of compromised third‑party accounts and contact addresses matching listings on the Cl0p data‑leak site, and victims have been shown alleged proof of access such as screenshots and file listings. Investigators say attackers appear to have abused compromised emails and Oracle password‑reset/default processes for internet‑facing EBS portals, though some experts caution an underlying software flaw or copycat actors could also explain the activity. Cybersecurity firm Halcyon and others report ransom demands in the seven‑ and eight‑figure range, with at least one demand reportedly as high as $50 million. Google and Mandiant say investigations are ongoing and they have not yet substantiated that data were exfiltrated; Oracle and the alleged actors have not commented. Security responders are assisting affected organizations and advising firms running internet‑facing Oracle EBS to review exposed portals, reset credentials, and monitor for suspicious activity.

Story Coverage
Bias Distribution
50% Right
Information Sources
daae85f0-2883-42fc-b085-888140adf30dbfb2a97b-336e-48d9-b69a-147df7862dc251dae2ab-6a3f-4156-b4a8-805de03e2b5037a048d0-d1c3-4045-a275-fea6b8818300
+2
Left 33%
C
Right 50%
Coverage Details
Total News Sources
6
Left
2
Center
1
Right
3
Unrated
0
Last Updated
2 days ago
Bias Distribution
50% Right
Related News
Ask VT AI
Story Coverage
Subscribe

Stay in the know

Get the latest news, exclusive insights, and curated content delivered straight to your inbox.

Present

Gift Subscriptions

The perfect gift for understanding
news from all angles.

Related News
Recommended News