A campaign attributed to the Cl0p operation exploited Oracle enterprise software during 2025, with affected organisations disclosing over the following months. Korean Air was among those reported to have disclosed a Cl0p-linked Oracle incident.
The Operating Model, Filed For The Fourth Year Running
Find a vulnerability in a widely-deployed enterprise product. Exploit every reachable instance in a short window. Extract data. Publish victims progressively over months to sustain pressure.
It is the managed-file-transfer pattern at 25-0214 and 26-0730, applied to a business application rather than a transfer tool. The corpus has recorded this shape often enough that it should be treated as a standing feature rather than an event.
Progressive Disclosure Is A Pressure Technique
Victims are named over an extended period rather than at once. That keeps the campaign in the news, gives each organisation time to watch peers being published before its own turn, and maximises the number of separate negotiations.
It also makes the campaign essentially uncountable in real time — this desk cannot say how many organisations were affected, and the answer will keep changing. It is the counting problem at 25-1230, engineered deliberately.
ERP Is The Worst Place For This To Happen
The corpus filed at 25-0424 that enterprise resource planning software is the system of record: general ledger, supplier master, payroll, inventory. Access requires no lateral movement to be valuable.
And it is the hardest software in an enterprise to patch quickly — heavily customised, integrated with everything, validated against business processes. The window between disclosure and exploitation at 25-1216 is shortest exactly where the ability to respond is slowest.
Graded Medium
The campaign is well reported in outline. This desk has not established the vulnerability chain, the total victim count, or the completeness of any published victim list.
Compiled from public reporting, listed below. Attribution follows those reports. Victim counts are incomplete by the nature of a progressive-disclosure campaign. Corrections: corrections@forensicpost.com.
- The biggest cybersecurity and cyberattack stories of 2025BleepingComputer
- Top 10 cyber-attacks of 2025Infosecurity Magazine