Skip to content

List of Oracle EBS Attack Victims May Be Growing Longer

Darkreading October 29, 2025

Numerous organizations have been attacked via Oracle EBS zero-day CVE-2025-61882, and evidence suggests more like Schneider Electric could be on that list.

The list of enterprises targeted by recent Oracle EBS attacks may also include Schneider Electric, Pan American Steel, and Cox Enterprises.

Earlier this month, the infamous ransomware-as-a-service gang Clop targeted customers affected by the critical Oracle E-Business Suite (EBS) zero-day vulnerability CVE-2025-61882. The flaw enables an unauthenticated attacker to remotely access and compromise Oracle Concurrent Processing. Exploiting this vulnerability can lead to follow-on activity such as data theft and possibly extortion. And in this case, early instances of extortion are part of the reason this zero-day came to light.

Patches for CVE-2025-61882 are available. Per an advisory , Oracle strongly recommended vulnerable customers apply the relevant security updates as soon as possible.

Clop is previously known for its attacks against a 2023 campaign against a zero-day in Progress Software's MOVEit Transfer managed file transfer (MFT) software, as well as attacks against Cleo customers. Beyond Clop, Google Threat Intelligence Group (GTIG) has suggested possible involvement from financially motivated threat group FIN11 (which has prior Clop association), but Google stopped short of a firm attribution, pending more concrete evidence.

It is unclear how many victims have been compromised as a result of Clop's campaign against Oracle EBS customers, though over the course of the month a few, such as Harvard University , have confirmed attacks. Based on Clop's data leak site and researcher reports, industry giants like Schneider Electric, Cox Enterprises, and Pan American Silver may all be affected.

On X, cybersecurity analyst and researcher Dominic Alvieri wrote that energy management vendor Schneider Electric SE had its stolen data leaked by FIN11 via Clop Ransomware. Alvieri similarly said publicly traded mining company Pan American Silver and communications giant Cox Enterprises had been targeted by Clop as part of CVE-2025-61882 attacks; both companies have been added to Clop's leak site.

Schneider Electric is unfortunately no stranger to threat actors claiming cyberattacks against them. Clop previously claimed an attack against the French multinational company as part of the MOVEit attacks in 2023, while a group known as Hellcat claimed a breach of Schneider last year . Meanwhile, Cox Enterprises subsidiary Cox Media Group was previously targeted by hackers in 2021.

Dark Reading contacted all three companies for , though none had responded at press time.

The exact blast radius of this campaign is difficult to determine, as Clop (which fundamentally cannot be trusted on its own) is still adding names to its data leak site and only a few organizations such as Harvard and Envoy Air (an American Airlines subsidiary) have disclosed attacks.

In the meantime, any organization that has not yet patched their Oracle EBS instances should immediately do so.

The FBI Cyber Division put it bluntly in a post to earlier this month. "The vulnerability allows unauthenticated attackers to execute code remotely over HTTP without user interaction. In plain terms: if your EBS environment is reachable on the network, and especially if it’s internet facing, it’s at risk for full compromise," the post read. "This is 'stop-what-you're-doing and patch immediately' vulnerability. The bad guys are likely already exploiting it in the wild, and the race is on before others identify and target vulnerable systems."

Senior News Writer, Dark Reading

Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Security, Nintendo World Report, and elsewhere. In his spare time, Alex hosts the weekly Nintendo podcast Talk Nintendo Podcast and works on personal writing projects, including two previously self-published science fiction novels.

Miercom Test Results: PA-5450 Firewall Wins

Security Without Compromise Better security, higher performance and lower TCO

The Total Economic Impact™ Of Palo Alto Networks NextGeneration Firewalls

How Enterprises Are Harnessing Emerging Technologies in Cybersecurity

Worldwide Security Information and Event Management Forecast, 2025--2029: Continued Payment for One's SIEMs

The Cloud is No Longer Enough: Securing the Modern Digital Perimeter

Securing the Hybrid Workforce: Challenges and Solutions

Cybersecurity Outlook 2026

Threat Hunting Tools & Techniques for Staying Ahead of Cyber Adversaries

Measuring Ransomware Resilience: What Hundreds of Security Leaders Revealed