Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

February 7, 2026

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

February 6, 2026
Facebook X (Twitter) Instagram
Saturday, February 7
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack
News

GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack

Team-CWDBy Team-CWDNovember 12, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


US-headquartered GlobalLogic has notified thousands of current and former employees that their data was compromised in a recent large-scale data extortion campaign.

According to a notification letter posted to the Office of the Maine Attorney General, the Hitachi-owned software company informed 10,471 individuals about the data breach, which targeted its Oracle E-Business Suite (EBS) platform.

“Oracle issued a security advisory on October 4, 2025, about a previously unknown zero-day exploit. GlobalLogic uses Oracle EBS, a collection of applications, to manage core business functions such as finance, HR, accounts payable and receivable,” the breach notification letter read.

“As soon as we learned of the vulnerability, GlobalLogic immediately investigated and determined that it had been exploited within our instance of Oracle.”

Read more on Oracle EBS campaign: NCSC: Patch Critical Oracle EBS Bug Now

The firm patched the zero-day bug, but its investigation confirmed that data had been exfiltrated on October 9 2025.

Oracle had confirmed that threat actors were likely exploiting “vulnerabilities” on October 2, with Google Mandiant confirming the news four days later.

Phishing Risk For Employees

“The personal information involved in this incident was from our Oracle platform, which includes HR information for current and former personnel,” the notification letter continued.

“That information includes personal information collected as part of Human Resources, and could involve the following information of yours: name, address, phone number, emergency contact (name and phone number), email, date of birth, nationality, country of birth, passport information, internal GlobalLogic employee number, national identifier or tax identifier such as Social Security Number, salary information, bank account information, and routing number.”

This kind of information would be a treasure trove for threat actors looking to launch follow-on phishing campaigns impersonating GlobalLogic and other organizations, or to commit identity fraud.

The firm didn’t share whether it had been contacted by the threat group behind the campaign, the notorious Cl0p outfit. However, Google said it’s aware of dozens of victims, although the final tally could be over 100.

The only other victim organizations to have been identified publicly to date are Harvard University and Envoy Air.

Image credit: CryptoFX / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCybercriminals Exploit Remote Monitoring Tools to Infiltrate Logistics and Freight Networks
Next Article Malicious VSX Extension “SleepyDuck” Uses Ethereum to Keep Its Command Server Alive
Team-CWD
  • Website

Related Posts

News

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

February 7, 2026
News

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026
News

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

What if your romantic AI chatbot can’t keep a secret?

November 18, 2025

Here’s what you should know

February 6, 2026

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.