Yazılar

Oracle Confirms Extortion Campaign Targeting Its E-Business Suite Customers

has confirmed that some users of its E-Business Suite software have received extortion emails from hackers, validating a warning first issued by Google earlier this week. In a Thursday blog post, the California-based tech giant said its internal investigation revealed potential exploitation of previously known software vulnerabilities and urged customers to upgrade their systems immediately.

The company did not specify how many clients were impacted, but Google described the campaign as “high volume”, suggesting a broad wave of attacks against enterprise users.

Cybersecurity experts have linked the operation to the ransomware group Cl0p, a notorious Russia-linked or Russian-speaking collective that operates under a ransomware-as-a-service model—leasing its malware tools to other cybercriminals for a share of the profits. In a message to Reuters, the group said “Oracle bugged up,” but declined to provide further details.

According to Halcyon’s Ransomware Research Center chief Cynthia Kaiser, recent extortion demands connected to the campaign range from millions to tens of millions of dollars, with the highest reaching $50 million.

Trend Micro, a Japanese cybersecurity firm, previously labeled Cl0p as a “trendsetter for its ever-changing tactics,” noting its rapid adaptation to new vulnerabilities and defenses.

The attacks come amid a surge in corporate cyber-extortion incidents, targeting firms with complex enterprise software systems that handle sensitive financial and operational data. Oracle’s swift public acknowledgment—unusual in such cases—signals the seriousness of the threat and the company’s attempt to reassure customers that patches and updates remain their best defense.

Stellantis reports data breach at third-party provider for North America

Stellantis, the parent company of Chrysler, said on Sunday it had detected unauthorized access at a third-party service provider supporting its North American customer service operations.

The company confirmed that the breach exposed only basic contact information, with no financial or highly sensitive personal data compromised. Stellantis did not specify how many customers were affected.

“Upon discovery, we immediately activated our incident response protocols … and are directly informing affected customers,” Stellantis said, adding that authorities have been notified. The automaker urged customers to remain vigilant against phishing attempts.

The breach is the latest in a growing wave of cyberattacks targeting automakers. Earlier this month, Jaguar Land Rover was forced to shut factories until September 24 after a major cyber incident disrupted retail and production operations.

The rise in attacks reflects the increasing vulnerability of the automotive industry, as digital platforms and connected services become more integral to customer operations and vehicle support systems.

Vietnam investigates cyberattack on creditors’ data

Vietnam’s National Credit Information Center (CIC), which is overseen by the State Bank of Vietnam, has suffered a cyberattack targeting its database of creditors’ information. Authorities said the breach involved unauthorized access aimed at stealing personal data such as identities, credit payments, risk assessments, and credit card details.

The cybersecurity agency confirmed the investigation is ongoing, while CIC separately notified financial institutions in a September 11 letter, suspecting that the attack was carried out by the hacker group Shiny Hunters—a collective notorious for targeting companies like Google, Microsoft, and Qantas.

Officials stressed that CIC’s systems remain functional, with no disruption to operations or visible damage. However, the scope of the data leak has not been disclosed. Vietnam’s central bank declined to comment, and Shiny Hunters could not be reached.

JPMorgan analysts warned that while the incident does not yet pose a systemic risk, it may lead to higher cybersecurity costs for Vietnamese banks and could potentially affect deposit flows if further breaches occur.

Vietnam has already been grappling with a rising wave of data leaks. A 2024 report by telecom giant Viettel noted that 14.5 million leaked accounts in Vietnam represented 12% of global total leaks, underscoring the country’s growing vulnerability to cybercrime.