Google and Mandiant Uncover Large-Scale Data Extortion Campaign Linked to CL0P Group
Google's Threat Intelligence Group (GTIG) and Mandiant have exposed a sophisticated extortion campaign exploiting vulnerabilities in Oracle's E-Business Suite (EBS). The operation, which began as early as July 2025, has resulted in the theft of significant volumes of customer data. Attackers, potentially affiliated with the CL0P extortion group, sent threatening emails to executives, demanding ransom payments under the threat of publishing stolen information.
The campaign Leveraged a zero-day vulnerability tracked as CVE-2025-61882, with exfiltration activities peaking on September 29, 2025. Emails originated from compromised third-party accounts and included contact addresses previously tied to CL0P's data leak site. Google's report highlights the growing sophistication of cybercriminal networks targeting enterprise systems.