HomeSecurityBlackmail emails claim Oracle E-Business Suite data theft

Extortion emails claim Oracle E-Business Suite data theft

Mandiant and Google are warning of a new campaign of extortion emails , where executives of large companies are receiving messages claiming that sensitive data has been stolen from Oracle E-Business Suite systems . The campaign appears to have started in late September 2025 and is still under the microscope of cybersecurity experts .

Oracle E-Business Suite

Genevieve Stark, head of cybercrime at GTIG, confirmed that this activity has been observed since September 29 or earlier, but investigations are in the early stages and the claims of data theft have not yet been substantiated.

Mass emails from compromised accounts

According to Charles Carmakal, CTO of Mandiant – Google Cloud, the campaign is characterized by a high volume of emails sent from hundreds of already compromised accounts. At least one of them has been previously linked to activity by FIN11, a known financially motivated group with a history of ransomware attacks and extortion.

See also: Detour Dog malware distributes Strela Stealer via DNS TXT Records

The use of compromised accounts allows perpetrators to increase the credibility of emails (for the alleged theft of Oracle E-Business Suite data), reducing the likelihood of being detected by security filters.

Evidence of connection to the Clop gang

The extortion emails include contact addresses that point to the Clop ransomware gang's data leak website , suggesting a possible connection to the group, known for exploiting zero-day vulnerabilities and aggressively disclosing stolen data.

However, Mandiant notes that there is currently insufficient evidence to prove actual data theft or direct involvement of Clop. Despite the similarities to previous tactics, the origin of the attacks remains uncertain.

Extortion emails claim Oracle E-Business Suite data theft
Extortion emails claim Oracle E-Business Suite data theft

Experts' warnings

Mandiant and GTIG recommend that all organizations receiving such emails:

  • Check their systems for signs of unusual access.
  • Investigate potential breaches in Oracle E-Business Suite.
  • Do not respond or interact with blackmail emails.

Oracle, asked about the possible existence of a new zero-day vulnerability that could explain the alleged data theft, has not yet issued an official response.

See also: Ukraine: XLL files distribute CABINETRAT malware

Who are the Clops?

The Clop ransomware group (also known as TA505 , Cl0p , or FIN11 ) emerged in March 2019, starting with a variant of the CryptoMix ransomware. Their method follows a familiar pattern:

  1. Penetration into corporate networks.
  2. Theft of critical data.
  3. Encryption of systems with ransomware.
  4. Blackmail for ransom in exchange for decryption and non-disclosure of data.

Since 2020, Clop has increasingly turned to exploiting zero-day vulnerabilities in file transfer platforms, which has allowed them to carry out mass attacks on hundreds of organizations worldwide.

Their largest businesses

Some of the Clop gang's most well-known operations include:

  • 2020: Zero-day exploit in the Accellion FTA platform, affecting approximately 100 organizations.
  • 2021: Attack on SolarWinds Serv-U FTP with zero-day exploit.
  • 2023: GoAnywhere MFT platform breach , with more than 100 organizations affected.
  • 2023 – MOVEit Transfer: Their largest campaign, with a zero-day exploit that affected 2,773 organizations internationally.
  • 2024: Two zero-day exploits in Cleo file transfer, with new mass leaks.

These actions have made Clop one of the most active and dangerous players in the ransomware space.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Extortion emails claim Oracle E-Business Suite data theft
Extortion emails claim Oracle E-Business Suite data theft

The international reaction

The US State Department has put a $10 million for information linking Clop to a foreign government, a move that shows how seriously the threat is being taken, not just as a criminal matter but also as a potential national security issue.

See also: Motility Software Solutions: Major data breach

The importance for businesses

Regardless of whether data was actually stolen, the new campaign shows the ease with which extortion groups can exploit fear and uncertainty to pressure organizations. The fact that the campaign targets executives and uses compromised email accounts shows that the perpetrators are investing in more realistic and persuasive social engineering methods.

Businesses using Oracle E-Business Suite are urged to immediately implement security controls, inform their teams about the risk of phishing, and prepare for potential real-world attacks on their network.

This case, regardless of whether it proves directly linked to Clop, shows how email extortion campaigns are evolving into a strategic threat to the business world. The combination of hacking techniques and psychological pressure makes companies vulnerable and necessitates investment in robust cybersecurity measures.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS