[thb_gap height=”50″]
Hackers tied to the Clop ransomware group are targeting executives at major companies with extortion emails, claiming to have stolen sensitive data from Oracle’s business software. Google says the emails began circulating on September 29, but investigators have not yet verified whether the breach occurred.
Targeting executives directly
The messages were sent from hundreds of compromised accounts and included contact details listed on Clop’s leak site, a portal the group uses to intimidate victims into paying. By threatening to publish stolen files, Clop has extracted tens of millions of dollars in past campaigns. In one recent case, the group demanded 50 million dollars from a single company, according to incident responders cited by Bloomberg.
Exploiting Oracle applications
The hackers are believed to have abused Oracle E-Business Suite, a widely used platform for managing employee and customer data. According to early findings, they used compromised email accounts and default password reset functions to obtain valid credentials for web portals accessible online. Oracle’s software supports thousands of organizations worldwide, putting a large pool of corporate data at risk. Oracle has not commented publicly on the incident.
A familiar pattern of large scale breaches
Clop is known for exploiting zero day flaws in enterprise software to strike multiple organizations simultaneously. Past operations have exposed data belonging to tens of millions of individuals. Google’s Mandiant unit confirmed that the same techniques and infrastructure seen in earlier Clop campaigns are present in this round of extortion emails.
The wider picture
This campaign underscores how ransomware groups are evolving their tactics. Rather than focusing only on encrypted files, attackers are targeting leadership directly with threats of exposure. Even without confirmed breaches, the claims themselves create fear and pressure inside organizations, forcing executives into difficult decisions.
The investigation is ongoing and no arrests have been made. Google says it is monitoring the campaign closely, while security firms warn that executives across multiple industries should remain on alert for tailored extortion attempts.