Oracle Probes Cl0p-Linked Extortion Campaign Targeting E-Business Suite
Oracle is investigating a series of hacks on its E-Business Suite customers, part of an extortion campaign exploiting vulnerabilities patched in July. The attacks, linked to the Cl0p ransomware group, began around September 29 and have compromised numerous organizations. Hackers have demanded up to $50 million in ransom and sent mass extortion emails. Oracle has acknowledged the issue and urged customers to apply security updates.

*this image is generated using AI for illustrative purposes only.
Oracle Corporation, a global leader in enterprise software, is currently investigating a series of hacks targeting its E-Business Suite customers. The attacks, which began around September 29, are part of an extortion campaign exploiting known software vulnerabilities that Oracle had previously addressed with patches released in July.
Widespread Impact on E-Business Suite Users
The E-Business Suite, a comprehensive platform used by thousands of companies worldwide for managing finance, supply chain, and customer relationships, has become the focal point of this cybersecurity breach. Attackers have successfully compromised the systems of numerous organizations, leveraging unpatched vulnerabilities to gain unauthorized access.
Cl0p Ransomware Group Connection
The hackers behind this campaign claim affiliation with the notorious ransomware group Cl0p. This group has a history of high-profile attacks, having previously compromised an estimated 3,000 organizations in the United States and 8,000 globally. Their activities have resulted in the theft of data pertaining to tens of millions of individuals.
Extortion Tactics and Demands
In their extortion attempts, the attackers have employed a multi-pronged approach:
- High-Value Ransoms: In at least one instance, the hackers demanded up to $50.00 million from a targeted organization.
- Mass Email Campaigns: Extortion emails were sent from hundreds of compromised accounts, amplifying the reach and impact of their threats.
Oracle's Response
Oracle's Chief Security Officer has acknowledged the company's awareness of the extortion emails. In response to the ongoing situation, Oracle has:
- Confirmed the investigation into the hacks.
- Urged customers to apply the necessary security updates, which were originally released in July.
Implications for Businesses
This incident underscores the critical importance of:
- Timely Patch Management: Promptly applying security updates to mitigate known vulnerabilities.
- Robust Cybersecurity Measures: Implementing comprehensive security protocols to protect against sophisticated attack vectors.
- Continuous Monitoring: Maintaining vigilance in detecting and responding to potential security breaches.
As the investigation unfolds, Oracle E-Business Suite users are advised to review their security posture, ensure all systems are up-to-date with the latest patches, and remain alert for any suspicious activities on their networks.