the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

Clop Hackers Target Execs with Oracle Data Breach Extortion

ArticlesNewsletters
ArticlesNewsletters
cybersecurity

Clop Hackers Target Execs with Oracle Data Breach Extortion

Ransomware group sends $50M extortion emails after claiming Oracle E-Business breach

by The Tech Buzz

PUBLISHED: Thu, Oct 2, 2025, 3:42 PM UTC | UPDATED: Thu, Sep 3, 2026, 4:58 PM UTC

Add as a preferred source on Google
Clop Hackers Target Execs with Oracle Data Breach Extortion

Google is warning that the notorious Clop ransomware gang is flooding executive inboxes with extortion demands after claiming to have breached Oracle E-Business Suite installations. The hackers started their campaign on September 29, targeting "numerous" large organizations with threats backed by alleged stolen data from Oracle's widely-used enterprise software. While Google hasn't confirmed the breach claims, the attackers are already demanding ransoms as high as $50 million.

The corporate world just got a harsh reminder that no enterprise software is immune from ransomware attacks. Google's cybersecurity teams are tracking an active extortion campaign where the Clop ransomware gang is directly targeting C-suite executives with claims they've compromised Oracle E-Business Suite installations.

Genevieve Stark, Google's head of cybercrime analysis, confirmed to TechCrunch that the campaign launched around September 29, with hackers sending personalized threats to executives at "numerous" large organizations. What makes this particularly concerning isn't just the scale - it's the sophistication of the attack vector.

According to Charles Carmakal, CTO of Google's Mandiant incident response unit, the malicious emails aren't random phishing attempts. They contain contact addresses directly lifted from Clop's data leak site, the same platform the gang uses to publicly shame victims into paying ransoms. This suggests the hackers have already accessed substantial amounts of corporate data and are now leveraging it for targeted extortion.

The financial stakes are enormous. Bloomberg reported that in at least one case, the attackers demanded $50 million from an affected company - a figure that underscores both the value of the stolen data and Clop's confidence in their position.

Advertisement

Clop has earned its reputation as one of the most prolific ransomware operations globally, responsible for breaching hundreds of companies through zero-day vulnerabilities - previously unknown security flaws that give them unprecedented access before patches exist. Their track record includes mass-hack campaigns that have exposed data on tens of millions of people, making them a household name in cybersecurity circles.

The attack methodology reveals a troubling evolution in ransomware tactics. Rather than encrypting systems and demanding payment for decryption keys, Clop is focusing on pure data extortion. According to Bloomberg's sources, the hackers exploited compromised user emails and abused Oracle's default password-reset function to gain legitimate credentials for Oracle E-Business Suite portals accessible from the internet.

This approach is particularly dangerous because Oracle E-Business Suite sits at the heart of many large organizations' operations. The software manages customer databases, employee information, human resources files, and other sensitive corporate data. Oracle's own website boasts that thousands of organizations worldwide rely on E-Business Suite to run their companies, making it an attractive target for ransomware groups seeking maximum impact.

The timing couldn't be worse for corporate security teams already stretched thin by an escalating cyber threat landscape. Unlike traditional ransomware attacks that immediately signal compromise through encrypted systems, data-only extortion can go undetected for weeks or months while hackers quietly exfiltrate sensitive information.

Advertisement

What's particularly concerning is the personalized nature of these executive-targeted campaigns. By directly threatening C-suite leaders with exposure of sensitive corporate and potentially personal information, Clop is applying maximum psychological pressure at the decision-making level. This represents a shift from broad-based attacks to surgical strikes designed to force rapid payment decisions.

The silence from Oracle adds another layer of uncertainty. Despite requests for comment, Oracle spokesperson Deborah Hellinger hasn't responded, leaving customers and security researchers without official guidance on potential vulnerabilities or recommended protective measures.

For enterprises running Oracle E-Business Suite, this incident highlights critical security gaps that extend beyond traditional perimeter defenses. The fact that hackers could abuse password-reset functions suggests that default configurations and internet-accessible portals create unnecessary attack surfaces that many organizations may not have adequately secured.

This Clop campaign represents a dangerous evolution in ransomware tactics - moving from system encryption to targeted executive extortion backed by stolen enterprise data. The $50 million ransom demands signal that ransomware groups view Oracle E-Business Suite breaches as particularly lucrative, given the sensitive corporate data these systems contain. For organizations running Oracle's enterprise software, this incident serves as a wake-up call to audit internet-accessible portals, strengthen authentication beyond default settings, and prepare incident response plans for data extortion scenarios that bypass traditional ransomware detection.

Advertisement

Advertisement

Trending Now

1

GoPro CEO Vows Cameras Stay Core After Starman Deal

2

Judge Splits Ruling in X vs. Twitter Rival Fight

3

Tim Cook Steps Down, Ternus Takes Apple's Helm

4

Google's Lyria 3.5 Brings AI Music to Gemini

5

Google Translate Gets Listening Mode, Live Background Mode

People Also Ask

Clop ransomware gang is demanding up to $50 million from companies after claiming to breach Oracle E-Business Suite installations. The hackers started their extortion campaign on September 29, directly targeting executives with personalized threats backed by allegedly stolen corporate data.

According to Bloomberg sources, Clop exploited compromised user emails and abused Oracle's default password-reset function to obtain legitimate credentials for Oracle E-Business Suite portals accessible from the internet, allowing them to access sensitive corporate data.

Oracle E-Business Suite manages customer databases, employee information, human resources files, and other sensitive corporate data. Oracle states that thousands of organizations worldwide rely on E-Business Suite to run their companies' core operations.

The Clop ransomware extortion campaign targeting Oracle E-Business Suite users began around September 29, 2025. Google's cybersecurity teams confirmed hackers started sending personalized threats to executives at numerous large organizations on this date.

Google's Mandiant team confirmed the extortion emails contain contact information from Clop's data leak site, suggesting legitimate breach claims. However, Oracle has not responded to requests for comment or provided official confirmation of any security breach.

Unlike traditional ransomware that encrypts systems for decryption payments, Clop is focusing on pure data extortion. They steal sensitive information and directly threaten executives with exposure, applying maximum psychological pressure at the decision-making level for rapid payment.

More in cybersecurity

How To Prevent Account Takeover?

How To Prevent Account Takeover?

Coupang CEO Resigns After 34M Customer Data Breach

Coupang CEO Resigns After 34M Customer Data Breach

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes Customer Info in App Config Error

Petco Data Breach Exposes Customer Info in App Config Error

Marquis Ransomware Attack Hits 400K+ Bank Customers

Marquis Ransomware Attack Hits 400K+ Bank Customers

Okta beats Q3 earnings as AI agent push drives growth

Okta beats Q3 earnings as AI agent push drives growth

More Articles

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Dec 2

Coupang Data Breach Hits 34M Users in Months-Long Attack

Coupang Data Breach Hits 34M Users in Months-Long Attack

Dec 1

London Councils Hit by Major Cyberattack, Emergency Plans Activated

London Councils Hit by Major Cyberattack, Emergency Plans Activated

Nov 26

Tyler Technologies jury system bug exposed juror data across US

Tyler Technologies jury system bug exposed juror data across US

Nov 26

Major Banks Assess Data Theft After SitusAMC Breach

Major Banks Assess Data Theft After SitusAMC Breach

Nov 24

Corporate America ditches passwords as 92% of CISOs go passwordless

Corporate America ditches passwords as 92% of CISOs go passwordless

Nov 23