Organisations named in connection with the Oracle EBS campaign include Schneider Electric, Emerson, Logitech, Cox Enterprises, Pan American Silver, LKQ Corporation, Copeland, The Washington Post and South Africa’s Wits University.
Industrial automation, process control, consumer peripherals, telecommunications, precious metals mining, vehicle parts distribution, a national newspaper and a university. There is no sector logic to that list, and that is the point.
Mass Exploitation Inverts Target Selection
Most files in this database describe an adversary choosing a victim and finding a way in. A zero-day campaign against widely deployed software works the other way: the vulnerability selects the victims, and the attacker discovers afterwards who they got.
That is why the list looks random. Membership was determined by running a particular ERP product, exposed in a particular way, during a two-week window.
It Defeats Threat Modelling As Commonly Practised
An organisation asking who would want to attack us and what would they want is doing something reasonable, and in this campaign it would have produced no useful answer.
A mining company is not an obvious target for a data-theft group. It was exploited anyway, because targeting was a property of its software estate rather than of its business. The defensive implication is that exposure inventory matters more than adversary modelling for this class of event.
Graded medium: victim names come from a mixture of company confirmations and leak-site listings, and we do not treat an unconfirmed listing as established.
Compiled from public reporting, listed below. Where a name appears only on the group’s leak site we treat it as an unverified claim. Corrections: corrections@forensicpost.com.