Teiss Michelin Confirms Data Breach from Oracle EBS Cyberattack
Article Content
- •Michelin confirmed a data breach linked to the Clop ransomware gang.
- •The breach involved exploitation of a zero-day vulnerability in Oracle E-Business Suite.
- •Over 315 GB of data was leaked, but Michelin stated no sensitive data was compromised.
Michelin has confirmed a data breach linked to the Clop ransomware gang's exploitation of vulnerabilities in Oracle E-Business Suite. The attack resulted in the compromise of localized data, although no sensitive or technical IT details were exposed. Clop previously leaked over 315 GB of data purportedly from Michelin's systems. The breach follows similar incidents affecting over 100 organizations, including Madison Square Garden, which reported a data leak of more than 210 GB. Michelin stated that all corrective actions were effectively implemented, and the situation is now resolved. The breach was attributed to a zero-day vulnerability in Oracle E-Business Suite, indicating a significant risk for organizations using this software. The company emphasized that its global systems remained unaffected by the attack.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Clop and Madison Square Garden in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
PaperCut NG/MF Vulnerability Under Active Exploitation On August 27, 2026, PaperCut issued an urgent advisory regarding a zero-day vulnerability affecting its NG and MF print management software. This flaw allows unauthenticated attackers to execute arbitrary Java code remotely, compromising server configurations. Emergency patches have been released for versions 25 and…