From late September 2025 the Cl0p group exploited CVE-2025-61882, a zero-day in Oracle E-Business Suite, in a mass extortion campaign. Extortion emails reached targets including Harvard University; the group later named 29 victims on its leak site.
Reported victims span sectors with little in common: universities, an airline subsidiary, a national newspaper, industrial manufacturers, a mining company, a consumer electronics firm. What they shared was an ERP deployment.
The Pattern Is The Group’s Signature, Not An Innovation
Cl0p has run this shape repeatedly: find a zero-day in a widely deployed enterprise file-transfer or business application, exploit it at scale in a short window, exfiltrate, then extort victims sequentially over months.
Nothing is encrypted. There is no operational disruption and no decryption key to sell. It is pure theft-and-publication — the model this desk described taking over from encryption at 26-0304, running here at industrial scale a year earlier.
ERP Is The Right Target For This Model
This desk filed the Estée Lauder Oracle EBS exposure at 26-0620 and made the point that enterprise resource planning holds payroll, identity documents and banking details for everyone on staff, while being exempted from the monitoring applied to customer-facing systems.
A single unauthenticated flaw in that class of software yields, per victim, the most sensitive internal dataset an organisation holds. Mass exploitation of it in a two-week window is an efficient use of a zero-day.
The Sequencing Is Deliberate
Naming victims one at a time over months, rather than publishing everything at once, keeps the campaign in the news and keeps pressure on organisations that have not yet been named but know they were exploited.
It also means the campaign’s true scope is unknown while it runs. The 29 named are those who did not pay or did not respond; the total exploited population is not public and probably never will be.
Compiled from public reporting and vendor analysis, listed below. Victim identification comes from the group’s own leak site and from company confirmations; where a name appears only on the leak site we treat it as a claim. Corrections: corrections@forensicpost.com.