Mandiant and Google are warning of a new campaign of extortion emails , where executives of large companies are receiving messages claiming that sensitive data has been stolen from Oracle E-Business Suite systems . The campaign appears to have started in late September 2025 and is still under the microscope of cybersecurity experts .

Genevieve Stark, head of cybercrime at GTIG, confirmed that this activity has been observed since September 29 or earlier, but investigations are in the early stages and the claims of data theft have not yet been substantiated.
Mass emails from compromised accounts
According to Charles Carmakal, CTO of Mandiant – Google Cloud, the campaign is characterized by a high volume of emails sent from hundreds of already compromised accounts. At least one of them has been previously linked to activity by FIN11, a known financially motivated group with a history of ransomware attacks and extortion.
See also: Detour Dog malware distributes Strela Stealer via DNS TXT Records
The use of compromised accounts allows perpetrators to increase the credibility of emails (for the alleged theft of Oracle E-Business Suite data), reducing the likelihood of being detected by security filters.
Evidence of connection to the Clop gang
The extortion emails include contact addresses that point to the Clop ransomware gang's data leak website , suggesting a possible connection to the group, known for exploiting zero-day vulnerabilities and aggressively disclosing stolen data.
However, Mandiant notes that there is currently insufficient evidence to prove actual data theft or direct involvement of Clop. Despite the similarities to previous tactics, the origin of the attacks remains uncertain.

Experts' warnings
Mandiant and GTIG recommend that all organizations receiving such emails:
- Check their systems for signs of unusual access.
- Investigate potential breaches in Oracle E-Business Suite.
- Do not respond or interact with blackmail emails.
Oracle, asked about the possible existence of a new zero-day vulnerability that could explain the alleged data theft, has not yet issued an official response.
See also: Ukraine: XLL files distribute CABINETRAT malware
Who are the Clops?
The Clop ransomware group (also known as TA505 , Cl0p , or FIN11 ) emerged in March 2019, starting with a variant of the CryptoMix ransomware. Their method follows a familiar pattern:
- Penetration into corporate networks.
- Theft of critical data.
- Encryption of systems with ransomware.
- Blackmail for ransom in exchange for decryption and non-disclosure of data.
Since 2020, Clop has increasingly turned to exploiting zero-day vulnerabilities in file transfer platforms, which has allowed them to carry out mass attacks on hundreds of organizations worldwide.
Their largest businesses
Some of the Clop gang's most well-known operations include:
- 2020: Zero-day exploit in the Accellion FTA platform, affecting approximately 100 organizations.
- 2021: Attack on SolarWinds Serv-U FTP with zero-day exploit.
- 2023: GoAnywhere MFT platform breach , with more than 100 organizations affected.
- 2023 – MOVEit Transfer: Their largest campaign, with a zero-day exploit that affected 2,773 organizations internationally.
- 2024: Two zero-day exploits in Cleo file transfer, with new mass leaks.
These actions have made Clop one of the most active and dangerous players in the ransomware space.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The international reaction
The US State Department has put a $10 million for information linking Clop to a foreign government, a move that shows how seriously the threat is being taken, not just as a criminal matter but also as a potential national security issue.
See also: Motility Software Solutions: Major data breach
The importance for businesses
Regardless of whether data was actually stolen, the new campaign shows the ease with which extortion groups can exploit fear and uncertainty to pressure organizations. The fact that the campaign targets executives and uses compromised email accounts shows that the perpetrators are investing in more realistic and persuasive social engineering methods.
Businesses using Oracle E-Business Suite are urged to immediately implement security controls, inform their teams about the risk of phishing, and prepare for potential real-world attacks on their network.
This case, regardless of whether it proves directly linked to Clop, shows how email extortion campaigns are evolving into a strategic threat to the business world. The combination of hacking techniques and psychological pressure makes companies vulnerable and necessitates investment in robust cybersecurity measures.
Source: www.bleepingcomputer.com
