‘Dozens’ of organizations had data stolen in Oracle-linked hacks

TechCrunch
TechCrunch
2M ago
36 views
Hackers have stolen data from numerous organizations by exploiting vulnerabilities in Oracle's E-Business Suite, according to Google researchers.
‘Dozens’ of organizations had data stolen in Oracle-linked hacks
A What happened
Google's security researchers have reported that the Clop extortion gang has successfully stolen data from numerous organizations by exploiting vulnerabilities in Oracle's E-Business Suite software. This hacking campaign, which dates back to at least July 10, targeted corporate executives with extortion emails. Oracle acknowledged that the hackers were still using its software to access sensitive personal information. Although Oracle's chief security officer initially suggested that the vulnerabilities had been patched, a recent advisory revealed that a zero-day bug was still being exploited. This bug allows hackers to access systems over a network without needing a username or password. The Clop gang is known for its mass-hacking campaigns, often leveraging previously unknown vulnerabilities to steal large amounts of data. Google's blog post provided technical details to help organizations identify potential compromises in their Oracle systems.

Key insights

  • 1

    Extortion Emails Target Executives: The hacking campaign specifically targeted corporate executives with extortion emails.

  • 2

    Zero-Day Vulnerability Exploited: A zero-day bug was exploited, allowing unauthorized access without credentials.

  • 3

    Clop Gang's Reputation: The Clop gang is notorious for mass-hacking campaigns leveraging unknown vulnerabilities.

Takeaways

The ongoing exploitation of Oracle's vulnerabilities highlights the persistent risks in cybersecurity.

Topics

Technology & Innovation Cybersecurity World & Politics Governance