Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Cox Confirms Oracle EBS Hack as Cybercriminals Name 100 Alleged Victims

More than 1.6 Tb of data allegedly stolen from Cox was made public by the hackers.

Cox Oracle hack

Cox Enterprises has confirmed that its Oracle E-Business Suite (EBS) instance was impacted in the recent cybercrime campaign that has targeted many organizations. 

Cox did not respond to SecurityWeek’s request for comment when it was listed as a victim of the Oracle EBS campaign on the Cl0p ransomware leak website in late October. However, it did confirm last week to the Maine Attorney General that it was targeted.

The company said the attackers obtained personal information belonging to nearly 9,500 individuals after breaching its Oracle EBS instance between August 9 and August 14.

Cox is a conglomerate with divisions focusing on communications, automotive services, and agriculture. It’s unclear which of these units were impacted by the data breach and whether the compromised information belongs to employees, customers, or partners.

The cybercriminals have made public 1.6 Tb of archives containing files allegedly stolen from Cox.

The number of organizations named on the Cl0p website — apparently as victims of the Oracle EBS hack — has exceeded 100, and nearly half of them are major companies in sectors such as IT, telecommunications, healthcare and pharmaceuticals, heavy industry and manufacturing, automotive and transportation, retail, energy and utilities, and media. 

Advertisement. Scroll to continue reading.

Organizations such as Logitech, The Washington Post, Harvard, Mazda, and American Airlines subsidiary Envoy Air have confirmed being targeted. 

However, other large companies have not responded to SecurityWeek’s requests for comment, including Schneider Electric, Emerson, Broadcom, Michelin, Bechtel, Canon, Entrust, LKQ Corporation, and Pan American Silver. 

The United Kingdom’s National Health Service (NHS) has confirmed conducting an investigation, but it has yet to confirm a data breach.  

Cl0p has been the public-facing group to take credit for the Oracle EBS campaign, but the cybersecurity community has linked the attacks to an unknown cluster of a threat actor tracked as FIN11, which was also responsible for similar operations targeting customers of Cleo, MOVEit, and Fortra file transfer products.         

Based on past incidents, organizations are not listed on the Cl0p website without cause, but the actual scope of the breach may be exaggerated by the threat actors to pressure victims into paying a ransom.    

Related: CISA Confirms Exploitation of Latest Oracle EBS Vulnerability

Related: Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.