Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Dirty Frag: The Linux Kernel Flaw That Hands Attackers Root Access

    June 22, 2026

    iOS 27 Liquid Glass: What Apple Actually Changed and Why

    June 22, 2026

    Withings Body Smart Review: A Smart Scale Worth the Money?

    June 22, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Uncategorized»Google says Russian hackers attacked over 100 companies using Oracle vulnerability
    Uncategorized

    Google says Russian hackers attacked over 100 companies using Oracle vulnerability

    Michael ComaousBy Michael ComaousJanuary 10, 2025Updated:January 5, 20263 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    One of the largest corporate data breaches of 2025

    Google revealed on Thursday that a massive cyberattack targeting Oracle’s enterprise software compromised dozens — and potentially more than 100 — organizations worldwide, marking one of the largest corporate data breaches of 2025.

    According to Google’s Threat Analysis Group, the attack was carried out by CL0P, a ransomware group linked to Russia, which exploited a zero-day vulnerability in Oracle’s E-Business Suite to steal sensitive business data and demand ransoms of up to $50 million per victim.

    The campaign, which began as early as July 2025, targeted critical Oracle systems used by thousands of companies to manage finances, payroll, and supply chains. Google security analyst Austin Larsen stated, “We’re aware of dozens of victims, but expect the number to be much higher. Based on the scale of CL0P’s past campaigns, it’s likely that more than a hundred organizations were affected.”

    Zero-day flaw enabled massive compromise

    Researchers from Google’s Threat Intelligence Group and Mandiant confirmed that CL0P exploited CVE-2025-61882, a critical vulnerability with a CVSS score of 9.8, allowing unauthenticated remote code execution. The first exploitation occurred on August 9, 2025, weeks before Oracle released an emergency patch on October 4.

    “This level of sophistication suggests the attackers invested significant time and resources into researching the flaw before launching the breach,” Google said. The vulnerability affected Oracle E-Business Suite versions 12.2.3 through 12.2.14, granting full system control without needing usernames or passwords.

    The attack chain involved bypassing authentication through Oracle’s SyncServlet, uploading malicious templates via the XML Publisher Template Manager, executing commands, and planting persistent backdoors. CL0P exfiltrated vast amounts of sensitive data — including payroll records, vendor contracts, and financial transactions — before sending ransom emails directly to corporate executives.

    Widespread corporate disruption and emergency response

    The breach forced many organizations to temporarily shut down ERP servers for forensic analysis and patching, disrupting payroll, order management, and financial reporting systems. Some companies faced delays applying the fix, as Oracle’s emergency update required a base patch from October 2023 to install properly.

    “Massive amounts of customer data” were compromised during the campaign, Google confirmed. The exposure raises serious compliance concerns under GDPR and CCPA, adding both financial and reputational risks for affected firms.

    After the vulnerability was disclosed publicly, exploit scripts began circulating online, prompting urgent warnings from cybersecurity agencies, including CISA, which added CVE-2025-61882 to its Known Exploited Vulnerabilities Catalog. Oracle has urged all E-Business Suite customers to apply the emergency patch immediately to prevent further exploitation.

    The growing wave of enterprise cyberattacks

    The Oracle breach comes amid a surge in high-profile corporate cyber incidents across the tech industry in 2025:

    • Salesforce recently refused to pay ransom demands after hackers exposed nearly one billion customer records, in what experts called one of the largest supply chain attacks on enterprise software platforms.
    • Microsoft confirmed that attackers exploited a critical flaw in Fortra’s GoAnywhere software, allowing ransomware deployments of Medusa.
    • Discord suffered a serious data breach after a hack on one of its third-party support vendors, leaking users’ personal information and government-issued IDs.

    Together, these incidents highlight the growing fragility of enterprise systems and the increasing sophistication of ransomware groups that exploit zero-day vulnerabilities in widely used corporate software.

    As cybersecurity experts warn, the Oracle incident underscores a stark reality: even the world’s most trusted enterprise platforms are not immune to the escalating global cyberwar.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Next Article Are There Cordless Vacuums With Replaceable Batteries?
    Michael Comaous
    • Website

    Michael Comaous is a dedicated professional with a passion for technology, innovation, and creative problem-solving. Over the years, he has built experience across multiple industries, combining strategic thinking with hands-on expertise to deliver meaningful results. Michael is known for his curiosity, attention to detail, and ability to explain complex topics in a clear and approachable way. Whether he’s working on new projects, writing, or collaborating with others, he brings energy and a forward-thinking mindset to everything he does.

    Related Posts

    4 Mins Read

    iPhone 17 Pro Charging: Charger Type & Speeds Explained

    5 Mins Read

    iPhone Air vs iPhone 17 Pro: Which Should You Buy?

    4 Mins Read

    uBlock Origin on Brave: Do You Need It? (2026 Setup Guide)

    4 Mins Read

    How to Block Twitch Ads with uBlock Origin (2026 Guide)

    5 Mins Read

    AT&T iPhone Trade-In Values 2026: How to Get Up to $1,100 Off

    7 Mins Read

    Does the Motorola Razr Have Wireless Charging — Features, Compatibility, and Verdict

    Top Posts

    The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

    August 4, 20251,127 Views

    Discord will require a face scan or ID for full access next month

    February 9, 2026769 Views

    Best Stores for Buying MP3 and Digital Music You Can Keep Forever

    August 2, 2025586 Views
    Stay In Touch
    • Facebook

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

    August 4, 20251,127 Views

    Discord will require a face scan or ID for full access next month

    February 9, 2026769 Views

    Best Stores for Buying MP3 and Digital Music You Can Keep Forever

    August 2, 2025586 Views
    Our Picks

    Dirty Frag: The Linux Kernel Flaw That Hands Attackers Root Access

    June 22, 2026

    iOS 27 Liquid Glass: What Apple Actually Changed and Why

    June 22, 2026

    Withings Body Smart Review: A Smart Scale Worth the Money?

    June 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2026 GeekBlog

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.