Executive Summary
In September 2025, Oracle confirmed that customers running E-Business Suite (EBS) were targeted by extortion emails attributed to the Clop ransomware gang, following exploitation of security vulnerabilities addressed in the July 2025 Critical Patch Update. Multiple executives at affected companies received emails demanding ransom, with Clop claiming to have exfiltrated confidential data from unpatched Oracle EBS instances. While Oracle has not formally verified the data theft, the vulnerabilities—three of which were remotely exploitable without authentication—enabled attackers to potentially access sensitive business documents and threaten public disclosure if ransoms were not paid.
This incident highlights a continued and escalating trend of ransomware groups leveraging zero-day and freshly patched vulnerabilities to target critical enterprise software. Organizations dependent on ERP and business process applications are increasingly at risk, underscoring the urgent need for rapid patching and advanced network-layer security controls.
Why This Matters Now
The Clop campaign demonstrates growing ransomware sophistication and speed in exploiting newly disclosed vulnerabilities, putting high-value enterprise assets at risk. Swift patch adoption, robust segmentation, and proactive threat detection have become critical as attackers increasingly weaponize extortion against core business systems.
Attack Path Analysis
The attackers exploited remotely accessible vulnerabilities in unpatched Oracle E-Business Suite systems to gain initial access. They likely escalated privileges to access sensitive application functions and data. Using lateral movement across workloads, they expanded their access within the cloud environment. The adversaries established command and control channels to manage the operation and exfiltrate sensitive files. Data was covertly exfiltrated from E-Business Suite systems; finally, they leveraged extortion, threatening to leak stolen data and demand ransom.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited unpatched, remotely accessible vulnerabilities (e.g., CVE-2025-30745/30746/50107) in E-Business Suite to gain initial foothold without credentials.
Related CVEs
CVE-2025-30745
CVSS 6.1An easily exploitable vulnerability in Oracle MES for Process Manufacturing allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data access and modification.
Affected Products:
Oracle MES for Process Manufacturing – 12.2.12, 12.2.13
Exploit Status:
proof of conceptCVE-2025-30746
CVSS 6.1A vulnerability in Oracle iStore's Shopping Cart component allows unauthenticated attackers with network access via HTTP to compromise the system, potentially resulting in unauthorized data access and modification.
Affected Products:
Oracle iStore – 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14
Exploit Status:
proof of conceptCVE-2025-50107
CVSS 6.1A vulnerability in Oracle Universal Work Queue's request handling component allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data access and modification.
Affected Products:
Oracle Universal Work Queue – 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Exfiltration Over C2 Channel
Phishing
Data Encrypted for Impact
Service Stop
Data Manipulation
Brute Force
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Timely Implementation of Security Patches
Control ID: 6.3.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management – Vulnerability and Patch Management
Control ID: Article 14(4)
CISA Zero Trust Maturity Model 2.0 – Continuous Patch and Vulnerability Management
Control ID: Asset Management – Patch and Vulnerability Management
NIS2 Directive – Security of Network and Information Systems – Supply Chain Security, Vulnerability Handling
Control ID: Article 21(2)(c)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Oracle E-Business Suite vulnerabilities expose financial institutions to Clop ransomware data theft, threatening customer financial data and regulatory compliance requirements.
Health Care / Life Sciences
Healthcare organizations using Oracle EBS face critical patient data exposure through Clop extortion attacks exploiting July 2025 vulnerabilities, violating HIPAA compliance.
Government Administration
Government agencies running Oracle E-Business Suite systems vulnerable to Clop ransomware data theft campaigns targeting unpatched July 2025 security flaws.
Manufacturing
Manufacturing companies face operational disruption and intellectual property theft through Clop attacks exploiting Oracle EBS vulnerabilities in core business systems.
Sources
- Oracle links Clop extortion attacks to July 2025 vulnerabilitieshttps://www.bleepingcomputer.com/news/security/oracle-links-clop-extortion-attacks-to-july-security-flaws/Verified
- Oracle Critical Patch Update Advisory - July 2025https://www.oracle.com/security-alerts/cpujul2025.htmlVerified
- NVD - CVE-2025-30745https://nvd.nist.gov/vuln/detail/CVE-2025-30745Verified
- NVD - CVE-2025-30746https://nvd.nist.gov/vuln/detail/CVE-2025-30746Verified
- NVD - CVE-2025-50107https://nvd.nist.gov/vuln/detail/CVE-2025-50107Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust controls—such as network segmentation, east-west workload isolation, strict egress enforcement, and threat detection—could have detected or blocked key attack phases. Mapping CNSF capabilities to the kill chain reveals multiple interception and detection points that would have otherwise constrained lateral movement and data exfiltration.
Control: Cloud Firewall (ACF)
Mitigation: Prevents public network exposure of vulnerable workloads.
Control: Zero Trust Segmentation
Mitigation: Limits attacker movement through least privilege and isolation.
Control: East-West Traffic Security
Mitigation: Detects or blocks unauthorized lateral movements in cloud environments.
Control: Inline IPS (Suricata)
Mitigation: Detects and blocks known C2 traffic and exploit signatures.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents or alerts on unauthorized data egress.
Provides rapid detection and incident response to extortion activity.
Impact at a Glance
Affected Business Functions
- Financial Management
- Supply Chain Management
- Customer Relationship Management
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive financial records, customer data, and supply chain information due to unauthorized access and data modification.
Recommended Actions
Key Takeaways & Next Steps
- • Apply critical security patches promptly to all public-facing business applications and services.
- • Deploy Cloud Firewalls and Zero Trust Segmentation to reduce attack surface and contain lateral movement.
- • Enable East-West Traffic Security and Inline IPS to monitor, detect, and block internal and external attack traffic.
- • Implement strict Egress Policy Enforcement to restrict unauthorized data exfiltration.
- • Leverage Threat Detection & Anomaly Response for real-time monitoring and rapid incident response across multicloud environments.



