Cox Enterprises is at the center of yet another major cyberattack, after notifying thousands of employees that their personal data was exposed in a hacker attack. The incident is linked to the exploitation of a security flaw in Oracle E-Business Suite — a critical platform for many businesses' back-office operations.

How the breach was detected
Although the attack occurred in mid-August, the company didn’t become aware of the breach until late September. On September 29, 2025, its systems detected suspicious activity, prompting the security team to launch a thorough internal investigation. Cox revealed that cybercriminals had exploited a zero-day vulnerability in Oracle E-Business Suite between August 9 and 14, gaining access to internal functions and data.
See also: Iberia reveals data breach
With more than 55,000 employees and revenues approaching $23 billion, Cox is one of the largest American conglomerates with operations in telecommunications, automotive and a range of international markets. Its broad operations make it a natural target for ransomware groups that prey on large-scale organizations.
Cl0p behind the attack
Although Cox did not name the perpetrators, the notorious group ransomware was quick to claim responsibility. The group claims to have exploited the CVE-2025-61882long before Oracle released an official patch on October 5. Cl0p has built its reputation on zero-day exploits, which sets it apart from other criminal groups that mostly reuse known exploits.
Their history is extensive: Cleo file transfer (2024), MOVEit and GoAnywhere MFT (2023), SolarWinds Serv-U FTP (2021), Accellion FTA (2020) — a list that resembles a chronology of the most high-profile cybersecurity incidents of recent years.

A vulnerability that affects a large number of organizations
The Cox breach is not an isolated incident. Similar attacks exploiting the exact same vulnerability have been confirmed by companies like Logitech, the Washington Post, GlobalLogic, Envoy Air, and even Harvard University. The Oracle E-Business Suite platform is used by thousands of organizations worldwide, making any security flaw in its software extremely dangerous.
See also: Ransomware attacks on retailers increase during the holidays
On October 27, Cl0p operators added Cox Enterprises to their dark web leak site. In fact, they listed 29 companies as new victims that same day, indicating that the zero-day exploitation is continuing apace.
What data was exposed?
Cox has sent notifications to 9,479 people, but it did not specify exactly what types of personal data were leaked. The company says it is still in the process of analyzing the stolen files, which could indicate a wide variety of sensitive information.
In an effort to limit the damage, Cox is offering identity theft protection and credit report monitoring services through IDX (free for 12 months). While this is common corporate practice following breaches, it also highlights the level of concern about what data may have ended up in the hands of the perpetrators.
What does this mean for businesses and users?
The Cox-Oracle case serves as yet another reminder that successful cyber defense requires constant vigilance. Zero-day vulnerabilities in commercial software that support critical business functions can be turned into “weapons” in the hands of organized groups.
See also: Broadcom: Cl0p breach via zero-day in Oracle EBS?

As attacks become more targeted and professional, organizations are being asked to strengthen processes anomaly detection, invest in faster incident response, and pressure software vendors for more frequent and effective security audits.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This case clearly shows how, in the era of digital supply chains, a single zero-day can cause a domino effect on the entire business community.
Source: www.bleepingcomputer.com
