Archetyp Links

Dark Mode

Article Details

Oracle in the sights of hackers.Extortion e-mail and hundreds of compromised corporate accounts

Published on October 3, 2025

The giants of Oracle and Google technology ended up in the center of a new extortion campaign that would be hitting companies all over the world. The hackers, affiliated to the Ransomware Gr0p group, would have sent blackmail e-mail to the customers of the Oracle e-business suite, a platform that manages the main operations such as the supply chain and relationships with customers.In offending messages, cybercriminals have threatened to disseminate the sensitive data of users if they are not paid huge ransoms. Read also cryptocurrency scam, a new phishing campaign is taking place The Hacker attack on Oracle Suite According to Halcyon, a company specialized in IT security, the hackers managed to violate user emails and to exploit the password reset function to obtain valid credentials for Oracle E-Business suite accessible online portals. The attacks would start at the end of September 2025 and stand out for the high level of customization.The messages come from compromised accounts and are built to seem credible, with references to the company's business activities. Google, who is monitoring the situation with his division of cybersicacy, however, explained that he had no sufficient evidence to confirm that the data were really stolen. The Cybercriminal CL0P group The hacker campaign is attributed to Fin11, a criminal group linked to the Ransomware Cl0p, already responsible in the past of large -scale attacks.Experts believe that this is an "Ransomware-AS-Service" operation, a phishing model in which hackers provide tools and infrastructures to other attackers in exchange for a percentage of profits.Rebunting requests start from several million dollars and, in some cases, up to 50 million can reach. "In the last few days we have observed CL0P requesting ransoms of very high amounts, reaching figures of seven or eight zeros," explained Cynthia Kaiser, vice -president of Halcyon."This group is known for the massive and discreet theft of data, a strategy that increases its contractual power during negotiations for redemption". CL0P has a long history of attacks on large companies through advanced dimalware use to encrypt files and ask for payments for their decrytation.In 2023, the group was accused of having exploited Moveit's vulnerability, a very popular data transfer software between companies and organizations, managing to subtract information from hundreds of companies, including high -level names such as Shell Plc, British Airways and the British Broadcasting Corporation (BBC). Read also all the ways in which hackers use artificial intelligence to defraud people The security measures of Oracle and Google Larry Ellison's company confirmed that some of its customers have received extortion messages, but reiterates that there is no evidence of a direct violation of its central systems.The company, however, invited to keep the software updated and install the available security patches. Google is also working on new defense solutions, such as systems based on artificial intelligence capable of detecting and blocking suspicious activities on Google Drive before they turn into real ransomware attacks. The scope of the operation is therefore wide and worrying.For experts it represents further confirmation of how computer crime is evolving towards increasingly sophisticated techniques, capable of putting even pressure from the technological sector under pressure such as, in this case, Oracle and Google.