The UK 's National Health Service (NHS) is investigating claims of a breach of its Oracle E-Business Suite (EBS) system , as hackers have published a list of over 40 alleged victims.

The breach appears to have targeted Oracle EBS, one of the most widely used enterprise resource management systems, which is widely used by large organizations to manage finance, human resources and other critical functions. The hackers claim to have gained access to sensitive data and information, which could be used for malicious purposes.
See also: Police target Rhadamanthys, VenomRAT & Elysium malware – Arrests also made in Greece
NHS response
“We are aware that the NHS has been listed on a website as a victim of a cyberattack, but no details have been released,” an NHS England spokesperson told SecurityWeek. “The cybersecurity team is working closely with the National Cyber Security Centre (NCSC) to investigate.”
The Oracle EBS hacking campaign came to light in early October, and within two weeks, cybercriminals began naming victims on the ransomware group Cl0p. The hackers have since released data allegedly stolen from organizations including Harvard University, American Airlines subsidiary Envoy Air, industrial giants Schneider Electric and Emerson, and the Washington Post.

The NHS is the latest organisation to be named on the leak website, which now lists more than 40 alleged victims of the Oracle EBS campaign. Data allegedly obtained from 25 targets has been published.
See also: CISA: WatchGuard Fireware flaw exposes 54,000 Fireboxes
One of the victims named is Hitachi subsidiary GlobalLogic. GlobalLogic confirmed that cybercriminals gained access to information on current and former employees, including names, addresses, contact information, dates of birth, passport details, social security numbers, salary details and bank account details. The company said the incident affects more than 10,000 people.
Oracle EBS Breaches: Concerns and Protection
Experts recommend that organizations strengthen the security of their systems. Protection measures include promptly updating systems with the latest security releases, reviewing access policies , and strengthening data protection measures.
The Oracle EBS breach comes at a time of heightened concerns about cybersecurity in the healthcare sector, as attacks on these organizations have increased dramatically in recent years. These attacks often aim to extract sensitive patient, which can be used for blackmail or other malicious activities.
See also: Amazon: Cisco ISE and Citrix NetScaler zero-day exploit

The NHS's collaboration with the NCSC highlights the seriousness of the situation and the need for immediate action. Authorities are working feverishly to identify the source of the breach and limit its impact.
This case highlights the need for continued vigilance and strengthening of cybersecurity measures, especially in critical sectors such as healthcare. Organizations are urged to invest in technologies and practices that will strengthen their resilience against such threats.
The investigation is ongoing and more information is expected to be released as authorities proceed with analyzing the data and assessing the impact of the breach.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
