Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Clop Ransomware Hits GlobalLogic Using Oracle Vulnerability
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Clop Ransomware Hits GlobalLogic Using Oracle Vulnerability

Highlights

  • Clop ransomware exploited Oracle E-Business Suite, impacting GlobalLogic and others.

  • Personal and financial data of employees was exposed in the breach.

  • GlobalLogic applied fixes, cooperated with authorities, and enhanced security steps.

Ethan Moreno
Last updated: 11 November, 2025 - 10:49 pm 10:49 pm
Ethan Moreno 2 hours ago
Share
SHARE

GlobalLogic, a digital engineering firm owned by Hitachi, recently confirmed exposure to a significant data breach targeting Oracle E-Business Suite users. The attack, carried out by the Clop ransomware group, compromised sensitive personal and employment data of nearly 10,500 current and former GlobalLogic employees. This incident, which traces its roots back to July, highlights growing risks faced by organizations that depend on enterprise software platforms. Companies emphasizing cybersecurity in digital operations now see renewed debate over how quickly security patches must be applied and communicated across affected users.

Contents
What Information Was Compromised in the Breach?How Did GlobalLogic and Oracle Respond?What Has Been the Broader Impact on Oracle Customers?

Reports of Oracle E-Business Suite vulnerabilities exploited by ransomware groups have surfaced several times over the years, most notably in attacks orchestrated by Clop and other threat actors. While earlier incidents impacted only a handful of businesses and tended to be quickly contained, the recent campaign has affected a much wider array of organizations. Notably, the latest breaches show a longer undetected period before public disclosure and notification, which may point to increased sophistication by attackers and a slower internal response due to the zero-day nature of the flaw. Unlike previous attacks, this round has involved extortion emails and a public data-leak site aimed at further pressuring victims.

What Information Was Compromised in the Breach?

The stolen data involves a broad range of employee records, including names, contact details, birth dates, nationality, identification numbers, salary figures, and banking information. This array of information creates potential risks for identity theft and other forms of cybercrime targeting affected individuals. The exposure was first detected by GlobalLogic on October 9, several months after the initial breach reportedly began in July.

How Did GlobalLogic and Oracle Respond?

Upon identifying the breach, GlobalLogic initiated a series of incident response measures, involving law enforcement and external investigation partners. The company also implemented Oracle’s security patch and reported the breach to regulatory authorities in California and Maine. GlobalLogic commented,

“This incident did not target or impact GlobalLogic’s systems outside our Oracle platform, and, based on industry reports, we are one of many Oracle customers believed to be impacted.”

Oracle, after confirming the vulnerability, released a security update and advised impacted users to apply mitigation solutions promptly.

What Has Been the Broader Impact on Oracle Customers?

Clop’s campaign has affected dozens of Oracle customers, according to cybersecurity analysts. Aside from GlobalLogic, companies such as Envoy Air, affiliated with American Airlines, also disclosed their own incidents—though Envoy Air stated their sensitive and customer data remained secure. A spokesperson for Envoy Air said,

“We have conducted a thorough review of the data at issue and have confirmed no sensitive or customer data was affected. A limited amount of business information and commercial contact details may have been compromised.”

The Clop group has reportedly demanded ransoms reaching up to $50 million, threatening public exposure of exfiltrated data if payment is not provided.

Analysis of this situation underscores persistent risks in the use of third-party enterprise systems. Cybercriminal groups continue to shift tactics, exploiting zero-day vulnerabilities and aiming for maximal impact through extortion techniques. Organizations relying on complex platforms like Oracle E-Business Suite face mounting pressure to strengthen monitoring and improve incident disclosure practices. For affected employees and partners, rapid communication and support in identity monitoring become crucial steps in damage control. Transparent, timely notification and a willingness to collaborate with law enforcement now play central roles in crisis response. As these incidents demonstrate, using robust patch management and layered defense strategies are essential measures to limit long-term harm from emerging cyber threats.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

Microsoft Fixes 63 Security Flaws, One Zero-Day Under Active Attack

Amazon Engages Outside Experts to Test NOVA AI Model Security

BigBear.ai Buys Ask Sage to Strengthen Secure AI in Defense Sector

Nation-State Attacker Steals F5 BIG-IP Source Code, Experts Analyze Risks

FBI Tracks Yanluowang Ransomware Operator Across Borders

Share This Article
Facebook Twitter Copy Link Print
Ethan Moreno
By Ethan Moreno
Ethan Moreno, a 35-year-old California resident, is a media graduate. Recognized for his extensive media knowledge and sharp editing skills, Ethan is a passionate professional dedicated to improving the accuracy and quality of news. Specializing in digital media, Moreno keeps abreast of technology, science and new media trends to shape content strategies.
Previous Article Sony Reports Bungie Misses Targets as Destiny 2 Sales Drop
Next Article Amazon Engages Outside Experts to Test NOVA AI Model Security

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Tesla’s Elon Musk Proposes Optimus Bot for Crime Deterrence
Electric Vehicle
HistoSonics Secures $250M Funding to Expand Edison Ultrasound System
Robotics
Sony Reports Bungie Misses Targets as Destiny 2 Sales Drop
Gaming
United Micro and Ceva Boost Car Connectivity with 5G RedCap Platform
IoT
Yann LeCun Starts New AI Venture as Meta Focuses on Superintelligence
AI Technology
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?