JAKARTA - The tech giant from California, Oracle, confirmed that a number of its Oracle E-Business Suite (EBS) customers had received extortion emails from a hacker.

In a blog post, Oracle explained that the attack took advantage of the software vulnerability that had previously been identified.

"Ongoing investigations have found potential use of vulnerabilities that have previously been identified and have been handled in the Critical Patch Update July 2025," wrote Rob Duhart, Chief Security Officer, Oracle Security.

Although he has not detailed the number of customers affected by the extortion email, Oracle urges customers to immediately update.

"Oracle reiterated its strong recommendations for customers to immediately implement the latest Critical Update Patch," the company said.

According to the Head of the Ransomware Research Center at cybersecurity firm Halcyon, Cynthia totaling, extortion demands from this kind of group usually range from millions to tens of millions of dollars.

He said the hacker groups related to the campaign were the cl0p, a ransomware network known for using a ransomware-as-a-service model, which leases their software and infrastructure to other cybercriminals with a profit-sharing system.

To Reuters, cl0p called Oracle "disturbing" their efforts, but declined to provide further details. The identity of the members and location of the group is not known to the public, but cybersecurity researchers have long assessed that CL0p is affiliated with Russian-language networks.


The English, Chinese, Japanese, Arabic, and French versions are automatically generated by the AI. So there may still be inaccuracies in translating, please always see Indonesian as our main language. (system supported by DigitalSiber.id)