Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Incidents

Envoy Air Hit By Oracle System Hack

October 20, 2025
Reading Time: 4 mins read
in Incidents
Experian Fined For Data Collection

The Cl0p ransomware group has published over 26 GB of archive files, claiming the data was stolen from American Airlines and listing the major carrier on its Tor-based leak website. However, the organization actually targeted appears to be American Airlines’ regional subsidiary, Envoy Air, which describes itself as the largest regional carrier for American Airlines, operating over 800 daily flights under the American Eagle brand. The attack is part of a larger cybercrime campaign focused on organizations that utilize Oracle’s E-Business Suite (EBS) enterprise management solution, a campaign that has been publicly claimed by Cl0p and linked to the cybercrime group FIN11.

Envoy Air has confirmed its systems were impacted by this specific Oracle EBS campaign. In a statement to the media, the Texas-based carrier acknowledged the breach but maintained that a thorough investigation showed no customer or other sensitive data was compromised. They admitted, however, that the hackers did manage to compromise “a limited amount of business information and commercial contact details.” The listing on the Cl0p site is typically reserved for organizations that have received extortion emails from the attackers but have subsequently refused to pay a ransom.

The Oracle EBS campaign has impacted multiple organizations, with Harvard University being the first confirmed victim. Since then, additional organizations have been named on the Cl0p leak website, including South Africa’s University of the Witwatersrand, Johannesburg, which has also publicly confirmed it was targeted and is working to determine the extent of the compromised data. In addition to these, the leak site also lists the industrial giant Emerson, though no data allegedly stolen from that company has been made public at the time of this report.

While the campaign is attributed to the Cl0p-FIN11 nexus, the exact technical details remain somewhat unclear. It is not publicly known which specific Oracle EBS vulnerabilities were exploited in the attack, though Oracle initially indicated that known flaws patched in July were involved. The company later released patches for two additional EBS vulnerabilities: a zero-day (CVE-2025-61882) that was apparently exploited in the campaign, and another flaw (CVE-2025-61884) that exposes sensitive data, although the company has not confirmed if the latter was also leveraged by the attackers.

Furthermore, attributing the attack with precision is complicated by the nature of the threat groups involved. Google’s Mandiant security team tracks several distinct clusters of malicious activity under the broad umbrella of FIN11, making it difficult to pinpoint exactly which specific subgroup is responsible for executing this particular campaign. Nonetheless, the continued publication of stolen files and the listing of new victims on the Cl0p leak site signals that the campaign remains active and the number of impacted organizations is likely to grow.

Reference:

  • AWS Outage Crashes Amazon PrimeVideo Fortnite Perplexity And Numerous Other Platforms
Tags: cyber incidentsCyber Incidents 2025Cyber threatsOctober 2025
ADVERTISEMENT

Related Posts

Leroy Merlin Reports Data Breach

ASUS Confirms Vendor Breach By Everest

December 5, 2025
Leroy Merlin Reports Data Breach

Marquis Breach Hits Over 780,000 People

December 5, 2025
Leroy Merlin Reports Data Breach

Leroy Merlin Reports Data Breach

December 5, 2025
Defender Outage Disrupts Threat Alerting

Freedom Mobile Customer Data Breach Exposed

December 4, 2025
Defender Outage Disrupts Threat Alerting

Penn Phoenix Data Breach Oracle Hack Now

December 4, 2025
Defender Outage Disrupts Threat Alerting

Defender Outage Disrupts Threat Alerting

December 4, 2025

Latest Alerts

Silver Fox Spreads ValleyRAT In China

Intellexa Leak Exposes Predator Zero Days

Hackers Exploit ArrayOS AG VPN Flaw

Record DDoS Linked To Massive Botnet

RSC Bugs Let Hackers Run Remote Code Now

WordPress Elementor Addon Flaw Exploited

Subscribe to our newsletter

    Latest Incidents

    ASUS Confirms Vendor Breach By Everest

    Marquis Breach Hits Over 780,000 People

    Leroy Merlin Reports Data Breach

    Freedom Mobile Customer Data Breach Exposed

    Penn Phoenix Data Breach Oracle Hack Now

    Defender Outage Disrupts Threat Alerting

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial