Desk live·
ForensicPost
Ransomware/Aviation/File 25-1017

Envoy Air Confirms It Was Caught in the Cl0p Oracle EBS Campaign

Envoy Air, the American Airlines subsidiary, confirmed it was caught in the Oracle EBS campaign. Group structures mean a breach at a subsidiary is a breach in the parent’s supply chain.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetEnvoy Air
ActorCl0p
S. Rosler9 min readConfidence: high2 sources reviewed

Envoy Air, the largest carrier operating under American Airlines, confirmed on 17 October 2025 that it was affected by the wave of attacks exploiting the Oracle EBS zero-day filed at 25-0930.

Subsidiaries Run Their Own Estates

A regional carrier within a major airline group typically operates its own back-office systems. That is a deliberate structure — separate operating certificates, separate labour arrangements, separate financials — and it means the parent’s security programme does not automatically extend to it.

From an attacker’s position that is an advantage. A subsidiary carries the parent’s brand association and data relationships while frequently running with a fraction of the parent’s security capability.

Aviation Appears Again Through The Back Office

This desk has now filed aviation through operational disruption at 25-0919 and 26-0406, through customer data at 26-0702 and 26-0327, and here through enterprise administration.

None of these touched flight-safety systems, and the separation between safety-critical and business systems in aviation is genuine and enforced. It is worth restating each time, because it is the reason a sector this heavily targeted has produced delays rather than danger.

How we reported this

Compiled from public reporting, listed below. The scope of affected data has not been established publicly. See 25-0930 for the campaign. Corrections: corrections@forensicpost.com.

Sources
  1. Envoy Air (American Airlines) confirms Oracle EBS 0-day breach linked to Cl0pHackRead
  2. Envoy Air data breach: Clop ransomware exploits Oracle E-Business Suite zero-dayRescana
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary