Desk live·
ForensicPost
Ransomware/Extortion/File 25-1110

Cl0p Oracle EBS Victim List Spans Schneider Electric, Logitech and Emerson

The Oracle EBS victim list spans Schneider Electric, Emerson, Logitech, Cox Enterprises, Pan American Silver, LKQ and Copeland. None was targeted for what it does.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetOracle EBS customers, multiple
ActorCl0p
D. Kennedy10 min readConfidence: medium2 sources reviewed

Organisations named in connection with the Oracle EBS campaign include Schneider Electric, Emerson, Logitech, Cox Enterprises, Pan American Silver, LKQ Corporation, Copeland, The Washington Post and South Africa’s Wits University.

Industrial automation, process control, consumer peripherals, telecommunications, precious metals mining, vehicle parts distribution, a national newspaper and a university. There is no sector logic to that list, and that is the point.

Mass Exploitation Inverts Target Selection

Most files in this database describe an adversary choosing a victim and finding a way in. A zero-day campaign against widely deployed software works the other way: the vulnerability selects the victims, and the attacker discovers afterwards who they got.

That is why the list looks random. Membership was determined by running a particular ERP product, exposed in a particular way, during a two-week window.

It Defeats Threat Modelling As Commonly Practised

An organisation asking who would want to attack us and what would they want is doing something reasonable, and in this campaign it would have produced no useful answer.

A mining company is not an obvious target for a data-theft group. It was exploited anyway, because targeting was a property of its software estate rather than of its business. The defensive implication is that exposure inventory matters more than adversary modelling for this class of event.

Graded medium: victim names come from a mixture of company confirmations and leak-site listings, and we do not treat an unconfirmed listing as established.

How we reported this

Compiled from public reporting, listed below. Where a name appears only on the group’s leak site we treat it as an unverified claim. Corrections: corrections@forensicpost.com.

Sources
  1. Cl0p ransomware gang names 29 Oracle EBS breach victimsPaubox
  2. Oracle E-Business Suite zero-day exploitation: inside Cl0p’s latest mass data extortion campaignBreached.company
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary