← Back to Feed

Addressing CL0P Extortion Campaign Targeting Oracle EBS CVE-2025-61882
CVE-2025-61882
October 5, 2025 · Cybereason · Severity: HIGH
This article details a CL0P extortion campaign targeting Oracle E-Business Suite using CVE-2025-61882. Cybereason's forensic investigations show CL0P gained unauthorized access between July and September 2025, exfiltrating data. The campaign culminated in widespread email extortion starting in late September 2025.
Cybereason is continuing to investigate. Check the Cybereason blog for additional updates.
Last update: Oct 7, 11am EST
Overview and What Cybereason Knows So Far
- July 2025, Oracle releases security updates including 309 patches, which included nine that addressed flaws/vulnerabilities in Oracle E-Business Suite (EBS).
- July 2025 (end of) through September 2025 (beginning of), Cybereason has assessed based on emerging evidence and ongoing forensic investigations, that CL0P orchestrated an Intrusion Path that allowed for unauthorized access to on-premise, customer-managed Oracle E-Business Suite (EBS) solutions, enumerated accessible and stored data, and conducted data exfiltration.
- September 2025 (end of) through October 2025 (beginning of), a widespread orchestrated email extortion campaigns emerged targeting users of on-premise, customer-managed Oracle E-Business Suite (EBS) and requesting contact with CL0P in order to not expose data allegedly exfiltrated.
- October 2025 (beginning of), Cybereason is aware of ongoing investigations in which CL0P has provided proof of data. CL0P does not appear to have named new victims associated with this incident as of October 4, 2025.
- October 5, 2025, Oracle confirms CVE-2025-61882 in Oracle E-Business Suite (EBS). This vulnerability was remotely exploitable without authentication (i.e., it can be exploited over a network without the need for a username and password). Successful exploitation can lead to remote code execution (RCE).
- October 7, 2025, Cybereason confirms earliest evidence of threat actor activity occurred August 9, but is subject to change based on ongoing investigations.
Key Takeaways
- CL0P orchestrated an intrusion path targeting Oracle EBS starting in July 2025.
- They exploited vulnerabilities patched in the July 2025 Oracle CPU to gain unauthorized access.
- Extortion campaigns emerged from September to October 2025 targeting on-premise Oracle EBS users.