GlobalLogic adigital engineering services provider owned by Hitachi, announced that it has suffered a major data breach affecting more than 10,000 current and former employees . The attack is linked to a zero-day vulnerability in Oracle E-Business Suite (EBS), which has already been exploited by cybercriminal groups in dozens of organizations worldwide.

The Santa Clara, California -based company operates more than 59 product development centers and serves hundreds of businesses in the technology , automotive and telecommunications sectors. The announcement of the breach has raised concerns in the tech world, as the incident appears to be part of a wider chain of attacks targeting companies with critical cloud infrastructure.
What happened – Oracle EBS vulnerability exploited
According to an official notification filed with the Maine Attorney General's office, attackers gained access to GlobalLogic's internal systems through a zero-day vulnerability in Oracle EBS. The company said the initial breach was detected on October 9, 2025, with traces of activity dating back to July of that year.
See also: Oracle EBS Hack: Nearly 30 victims on Cl0p leak site
The stolen data includes personal employee information, such as names, addresses, dates of birth, nationality, social security numbers, bank accounts and payroll information. In addition, emergency contact information, emails and passports were stolen, making the incident particularly vulnerable to theft identity.
The company stressed that the incident did not affect any of its systemsother than the Oracle platform, and that many other Oracle customers appear to have fallen victim to the same campaign.
Connection to the Clop ransomware gang
Although GlobalLogic has not officially claimed responsibility, security experts believe the incident bears all the hallmarks of the Clop ransomware gang. The group, which has been active for years, is said to have exploited CVE-2025-61882, a serious flaw in Oracle EBS, to steal data and extort money from companies.
See also: Android Trojan 'Fantasy Hub' turns Telegram into a hub for hackers

Clop is known for its ransomware campaigns that have targeted large organizations such as Accellion, GoAnywhere MFT, MOVEit Transfer , and Cleo. These attacks have resulted in data leaks for millions of users worldwide.
So far, GlobalLogic has not been added to the Clop leak site on the dark web — suggesting either that the company is negotiating with the perpetrators or that it has already paid a ransom to prevent the data from being released.
A new wave of cyberbullying
The GlobalLogic case is yet another episode in the escalating cybersecurity crisis involving enterprise software platforms. Zero-day exploits, like the one on Oracle EBS, offer attackers a window of opportunity before software vendors release security updates.
The Clop gang has expanded its operations to include universities, newspapers, and airlines. According to Google Threat Intelligence Group, dozens of organizations have already been affected, with data from Harvard University and the Washington Postleaked online.
The US State Department has announced a $10 million reward for information that could link the Clop gang to foreign governments, underscoring the seriousness of the threat.
See also: Abuse of RMM tools to distribute Medusa & DragonForce ransomware
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Implications and lessons for the market
The attack on GlobalLogic highlights the deep dependence of businesses on third-party software providers and the need for multi-layered protection beyond the company's own walls.
The use of platforms, such as Oracle EBS, entails risks that must be addressed through constant monitoring, timely system updates , and staff training.

Experts emphasize that companies cannot assume that the responsibility for security stops with their suppliers. Comprehensive risk management and proactive threat hunting are now critical practices for any organization relying on cloud infrastructure.
The GlobalLogic case proves that even leading technology providers can find themselves at the center of a large-scale cyberattack.
As artificial intelligence and data centers become the “heart” of the global digital economy, threats of this type will continue to increase — and businesses will need to treat the possibility of a breach not as a possibility, but as an inevitable reality.
