< ciso
brief />
Tag Banner

All news with #clop tag

29 articles

GE and Philips probe alleged Clop ransomware breach

๐Ÿ” General Electric and Philips are investigating claims that the Clop ransomware gang breached their systems and stole data. Philips confirmed an attempted compromise of an internal enterprise server that has been contained and said there was no impact on customer environments. GE acknowledged awareness of the claim and is assessing the potential issue. The incidents are linked to Clopโ€™s exploitation of a PTC Windchill and FlexPLM vulnerability (CVE-2026-12569) that has prompted emergency advisories and active threat confirmations.
read more โ†’

Shell Probes Possible Data Theft After Clop Claims

๐Ÿ”Ž Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data, including engineering drawings and project plans. A Shell spokesperson confirmed awareness and said security teams and external experts are examining the matter. Clop listed Shell among 43 victims allegedly targeted via a PTC Windchill and FlexPLM vulnerability tracked as CVE-2026-12569. PTC, CISA, and other authorities have warned of active exploitation and urged urgent patching and mitigations.
read more โ†’

Cl0p affiliates exploit PTC Windchill and FlexPLM flaws

๐Ÿ”’ Threat actors tied to the Cl0p group are exploiting internet-exposed PTC Windchill and FlexPLM deployments to achieve unauthenticated remote code execution and deploy JSP web shells. According to a coordinated advisory from Ransom-ISAC, eCrime.ch, and DEFUSED, attackers chain a FlexPLM WSDL information disclosure with a Windchill login servlet flaw (CVE-2026-12569) to stage data theft and double extortion. Targets include manufacturing, automotive, aerospace, and retail organizations, with multiple IoCs published by PTC.
read more โ†’

Estรฉe Lauder discloses Oracle Eโ€‘Business Suite breach

๐Ÿ›ก๏ธ Estรฉe Lauder is notifying individuals after discovering that an unauthorized actor accessed its Oracle E-Business Suite HR system on or around August 9, 2025, exposing personal information. The company's investigation concluded on June 19, 2026, and the exposed data may include names, contact details, SSNs, passport numbers, bank account and health information. The breach correlates with mass exploitation tied to CVE-2025-61882 and activity by the Clop group; affected individuals are being offered 24 months of identity monitoring through Kroll.
read more โ†’

Korean Air Data Breach Exposes Thousands of Employees

๐Ÿ”“ Korean Air warned employees that personal information, including names and bank account numbers, was compromised after its former in-flight catering supplier, Korean Air Catering & Duty-Free (KC&D), notified the carrier it had been hacked. Local outlets report about 30,000 records were exfiltrated, and the Clop ransomware gang has claimed responsibility and posted the alleged data on its leak site. Korean Air reported the incident to authorities, is investigating the scope, and urged staff to remain vigilant for phishing and impersonation attempts.
read more โ†’

Clop-linked Breach Exposes 3.5M University of Phoenix Data

๐Ÿ”’ University of Phoenix disclosed a breach affecting 3,489,274 individuals after attackers accessed its systems in August and stole sensitive personal and financial data. Investigators say the intrusion targeted the Oracle E-Business Suite, exploiting a zero-day tracked as CVE-2025-61882, active August 13โ€“22 and detected November 21. The university is offering 12 months of credit and dark web monitoring, identity recovery and a $1m fraud reimbursement. The incident is linked to Clop and forms part of a wider campaign that has hit more than 100 organizations.
read more โ†’

Top Ransomware Trends of 2025: Activity and Impact

๐Ÿ” Ransomware activity in 2025 remained high, with 306 groups and 7,902 victims listed on data leak sites, according to Ransomware.live. While coordinated takedowns and anti-cybercrime actions were quieter than in 2024, both emergent collectives (Scattered Spider, Lapsus$, ShinyHunters) and established syndicates continued to generate incidents. The most prolific actors โ€” Qilin, Akira and Clop โ€” claimed the largest shares of victims, and the United States accounted for nearly half of the reported targets.
read more โ†’

Clop Breach Exposes Nearly 3.5M University of Phoenix Records

๐Ÿ”’ The University of Phoenix disclosed that the Clop ransomware gang stole personal and financial data for 3,489,274 people after exploiting a zero-day in the Oracle E-Business Suite. The university says names, contact details, dates of birth, Social Security numbers, and bank routing and account numbers were accessed. UoPX detected the intrusion after Clop posted the stolen files and is offering complimentary identity protection and a $1 million fraud reimbursement policy.
read more โ†’

Clop Targets Internet-Exposed Gladinet CentreStack Servers

๐Ÿ”’ The Clop ransomware gang is actively targeting Internet-exposed Gladinet CentreStack file servers in a new extortion campaign, with incident responders reporting ransom notes on compromised systems. Gladinet has issued multiple security updates since April to address several flaws, some disclosed as zero-days. It remains unclear whether Clop is exploiting a fresh zero-day or targeting unpatched instances. Threat data shows 200+ IPs exposing CentreStack login pages and potentially at risk.
read more โ†’

University of Pennsylvania Confirms Oracle EBS Data Theft

๐Ÿ”’ The University of Pennsylvania disclosed that attackers exploited a previously unknown Oracle E-Business Suite zero-day in August to obtain files containing personal information. In a notification filed with Maine's Attorney General, Penn said at least 1,488 individuals had data taken and warned the overall total may be larger. The university reported no evidence so far that the stolen information has been misused or published and has not publicly attributed the intrusion; the incident aligns with a broader campaign linked to the Clop ransomware group.
read more โ†’

Dartmouth Confirms Data Breach After Clop Extortion

๐Ÿ”’ Dartmouth College says threat actors linked to the Clop extortion gang exploited a zero-day in Oracle E-Business Suite to steal files and leak them on a dark web site. The college reported unauthorized access between August 9 and August 12, 2025, and on October 30 identified files containing names and Social Security numbers. A filing with Maine's Attorney General lists 1,494 individuals whose data was found in reviewed files and notes that financial account information was also taken. Dartmouth has not provided details on any ransom demand or the full scope of impacted people.
read more โ†’

Cox Enterprises Discloses Oracle E-Business Suite Breach

๐Ÿ”’ Cox Enterprises says hackers accessed its network after exploiting a zero-day in Oracle Eโ€‘Business Suite, with activity occurring between Aug. 9โ€“14 and detected on Sept. 29, 2025. The company notified 9,479 impacted individuals and is offering 12 months of credit monitoring and identity protection through IDX. The Cl0p ransomware gang has claimed responsibility and posted stolen files after Oracle issued a patch on Oct. 5. Cox did not specify the types of data exposed in the notice.
read more โ†’

Logitech Confirms Data Breach After Clop Extortion Campaign

๐Ÿšจ Logitech International S.A. confirmed a data breach claimed by the extortion gang Clop and disclosed the incident in a Form 8โ€‘K filing with the U.S. SEC. The company says data was exfiltrated but that the incident has not impacted its products, business operations, or manufacturing, and that highly sensitive fields such as national ID numbers and credit card data were not stored or accessed. Logitech engaged external cybersecurity firms, attributes the intrusion to a thirdโ€‘party zeroโ€‘day that was patched, and Clop has posted nearly 1.8 TB of alleged stolen data.
read more โ†’

Washington Post Oracle Breach Exposes Nearly 10,000

๐Ÿ”’ The Washington Post says a zero-day in Oracle E-Business Suite was used to access parts of its network, exposing personal and financial records for 9,720 employees and contractors. The intrusion occurred between July 10 and August 22, and attackers attempted extortion in late September. The activity has been tied to the Clop group exploiting CVE-2025-61884, and impacted individuals are being offered 12 months of identity protection and advised to consider credit freezes.
read more โ†’

GlobalLogic Confirmed as Victim of Cl0p Oracle EBS Exploit

๐Ÿ”’ GlobalLogic has notified 10,471 current and former employees that their data was exposed after a zero-day in Oracle E-Business Suite (EBS) was exploited in early October 2025. The company says it patched the vulnerability after confirming data exfiltration on 9 October. Stolen records reportedly include HR and payroll details such as names, dates of birth, passport numbers, salary, bank account and routing numbers, creating a high risk of follow-on phishing and identity fraud. GlobalLogic did not confirm contact by the extortion group, while security firms link the incident to Cl0p, which has targeted dozens of organizations including Harvard and Envoy Air.
read more โ†’

GlobalLogic warns 10,000 employees of Oracle data theft

๐Ÿ”’ GlobalLogic is notifying 10,471 current and former employees that personal data was stolen after attackers exploited an Oracle E-Business Suite zero-day. The compromised HR information includes names, contact details, birthdates, passport and tax identifiers, salary and bank account information. The incident aligns with a wider extortion campaign linked to the Clop ransomware group exploiting CVE-2025-61882.
read more โ†’

Envoy Air Confirms Oracle E-Business Suite Data Theft

๐Ÿ”’ Envoy Air confirmed that data was compromised from its Oracle E-Business Suite application after the Clop extortion gang listed American Airlines on its leak site. The carrier said it immediately launched an investigation, contacted law enforcement, and determined that no sensitive or customer data were affected, though limited business information and commercial contact details may have been exposed. The incident is tied to an August campaign by Clop, which exploited an E-Business Suite zeroโ€‘day (CVEโ€‘2025โ€‘61882) and is now publishing claimed stolen files.
read more โ†’

Google: Clop Exfiltrated Data via Oracle E-Business Flaw

๐Ÿ” Google Threat Intelligence and Mandiant report the Clop (FIN11) actor likely exfiltrated a significant amount of data from Oracle E-Business Suite environments beginning as early as August 9, 2025. The group sent extortion emails to executives from September 29 and supplied legitimate file listings to substantiate claims. Attackers exploited the zero-day CVE-2025-61882 prior to an emergency patch released on October 4, 2025. Investigators advise urgent patching, hunting for malicious templates, restricting outbound EBS traffic, and performing Java memory forensics.
read more โ†’

Cl0p-Linked Actors Exploit Oracle E-Business Suite

๐Ÿ”” Google Threat Intelligence Group and Mandiant report a multi-stage zero-day campaign exploiting Oracle E-Business Suite (tracked as CVE-2025-61882, CVSS 9.8) that has impacted dozens of organizations since August 2025. The attackers combined SSRF, CRLF injection, authentication bypass and XSL template injection to achieve remote code execution and deploy multi-stage Java loaders. Observed payloads include GOLDVEIN.JAVA and a SAGEGIFT/SAGELEAF/SAGEWAVE chain; orchestration and extortion messaging bear the Cl0p signature. Oracle has released patches and investigations by GTIG and Mandiant are ongoing.
read more โ†’

Oracle EBS Zero-Day Exploitation and Extortion Campaign

โš ๏ธ GTIG and Mandiant tracked a large-scale extortion campaign beginning Sept. 29, 2025, in which actors claiming affiliation with the CL0P brand alleged theft from Oracle Eโ€‘Business Suite (EBS) environments. Analysis indicates exploitation of a zero-day (CVE-2025-61882) as early as Aug. 9, 2025, with suspicious activity dating back to July 10. Attackers abused UiServlet and SyncServlet flows, embedding Java payloads via XSL templates to achieve unauthenticated RCE and deploy in-memory implants. Organizations are urged to apply Oracle emergency patches, hunt for malicious templates in XDO_TEMPLATES_B/XDO_LOBS, and restrict outbound traffic to disrupt C2.
read more โ†’