Desk live·
ForensicPost
Ransomware/Exploitation/File 25-1003

The Oracle Campaign Named Another One

Logitech confirmed a breach in November 2025 arising from a zero-day in a third-party platform, in the Cl0p extortion campaign against Oracle E-Business Suite recorded at 25-1007.

Constructed geometry · not a chart of case data
TargetLogitech
ActorCl0p
D. Kennedy11 min readConfidence: high3 sources reviewed

Logitech confirmed in November 2025 that an unauthorised third party had used a zero-day vulnerability in a third-party software platform to copy data from its internal IT systems, including limited information about employees, consumers, customers and suppliers. The Cl0p extortion group claimed the attack as part of its Oracle E-Business Suite campaign.

Exploited In July, Disclosed In November

The corpus filed the campaign model at 25-1007: exploit every reachable instance in a short window, then name victims progressively over months to sustain pressure and maximise separate negotiations.

Logitech is that model working. The exploitation was months earlier; the disclosure came when the company was named. For most of that interval the organisation was a victim of an incident that had already happened and had not yet surfaced.

It makes the campaign uncountable in real time, per 25-1230, and it is engineered rather than incidental.

The Disclosure Is Unusually Complete About Who Was Affected

Employees, consumers, customers and suppliers. Four populations named.

This desk filed at 25-0704 that workforce data is systematically under-recorded and at 25-1204 that supplier and commercial data triggers nothing. A company naming all four in one statement is describing the actual contents of an ERP estate — the point at 25-0424 that this is the system of record, not a copy of something.

A Zero-Day Does Not Settle The Question

This desk argued at 25-0214 that a previously unknown vulnerability genuinely limits what a customer could have prevented, and does not answer why the product was internet-reachable, why data persisted on it, or whether exfiltration would have been detected without being told.

Those remain architecture and retention decisions the customer owned, and they determine what a zero-day is worth to whoever finds it.

How we reported this

Compiled from public reporting and company disclosure, listed below. Volume claims made by the extortion group are not established and are not repeated here as fact. Corrections: corrections@forensicpost.com.

Sources
  1. Logitech confirms data breach after Clop extortion attackBleepingComputer
  2. Logitech confirms data breachHelp Net Security
  3. Logitech cybersecurity disclosureLogitech
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary