Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware

Google Mandiant and Google Threat Intelligence Group (GTIG) have revealed that they are monitoring a new cluster of activity that may be connected to Cl0p, a threat actor with financial motivations.

Sending extortion emails to executives at different companies while claiming to have stolen confidential information from their Oracle E-Business Suite is the harmful action.

In a statement to The Hacker News, Genevieve Stark, Head of Cybercrime and Information Operations Intelligence Analysis at GTIG, stated that although this activity started on or before September 29, 2025, Mandiant’s experts are still in the early phases of several investigations and have not yet verified the group’s claims.

The ongoing activity was characterized by Mandiant CTO Charles Carmakal as a “high-volume email campaign” that originates from hundreds of compromised accounts read more about Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *