Google statement on cyberattack: Data from dozens of companies

In a blog post published by Google, it was stated that the Google Threat Intelligence Group (GTIG) and the cybersecurity firm Mandiant began tracking a large-scale extortion campaign by a threat actor linked to the data leak site "CL0P" as of September 29.

12punto

In its analysis of the cyberattack targeting applications that enable the execution of Oracle's corporate business processes, Google noted that numerous organizations were affected and a significant amount of data was exfiltrated.

The post stated that the threat actor in question sent intensive emails to senior executives at numerous organizations, claiming to have stolen sensitive data from Oracle E-Business Suite (EBS) environments that facilitate the execution of corporate business processes.

The post recalled that Oracle announced on October 2 that attackers may have exploited vulnerabilities patched in July 2025 and advised its customers to apply the latest critical patch updates, while also noting that the company announced on October 4 that emergency patches must be applied to address this vulnerability.

The post stated that the analysis shows the CL0P extortion campaign took place following months of infiltration activities targeting EBS customer environments, and noted that threat actors had been exploiting a vulnerability in Oracle EBS since August 9.

The post also reported that suspicious activities dating back to July 10 were detected, and in some cases, attackers managed to exfiltrate significant amounts of data from the affected organizations.