Desk live·
ForensicPost
Ransomware/Exploitation/File 25-1007

One Enterprise Application, Victims on Four Continents

A campaign linked to the Cl0p operation exploited Oracle enterprise software during 2025, producing disclosures from organisations including Korean Air. It is the year’s clearest instance of the pattern.

Constructed geometry · not a chart of case data
JurisdictionSouth Koreathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetOracle enterprise estates
ActorCl0p
D. Kennedy12 min readConfidence: medium2 sources reviewed

A campaign attributed to the Cl0p operation exploited Oracle enterprise software during 2025, with affected organisations disclosing over the following months. Korean Air was among those reported to have disclosed a Cl0p-linked Oracle incident.

The Operating Model, Filed For The Fourth Year Running

Find a vulnerability in a widely-deployed enterprise product. Exploit every reachable instance in a short window. Extract data. Publish victims progressively over months to sustain pressure.

It is the managed-file-transfer pattern at 25-0214 and 26-0730, applied to a business application rather than a transfer tool. The corpus has recorded this shape often enough that it should be treated as a standing feature rather than an event.

Progressive Disclosure Is A Pressure Technique

Victims are named over an extended period rather than at once. That keeps the campaign in the news, gives each organisation time to watch peers being published before its own turn, and maximises the number of separate negotiations.

It also makes the campaign essentially uncountable in real time — this desk cannot say how many organisations were affected, and the answer will keep changing. It is the counting problem at 25-1230, engineered deliberately.

ERP Is The Worst Place For This To Happen

The corpus filed at 25-0424 that enterprise resource planning software is the system of record: general ledger, supplier master, payroll, inventory. Access requires no lateral movement to be valuable.

And it is the hardest software in an enterprise to patch quickly — heavily customised, integrated with everything, validated against business processes. The window between disclosure and exploitation at 25-1216 is shortest exactly where the ability to respond is slowest.

Graded Medium

The campaign is well reported in outline. This desk has not established the vulnerability chain, the total victim count, or the completeness of any published victim list.

How we reported this

Compiled from public reporting, listed below. Attribution follows those reports. Victim counts are incomplete by the nature of a progressive-disclosure campaign. Corrections: corrections@forensicpost.com.

Sources
  1. The biggest cybersecurity and cyberattack stories of 2025BleepingComputer
  2. Top 10 cyber-attacks of 2025Infosecurity Magazine
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary