WASHINGTON: Alphabet's Google said hackers are sending extortion emails to an unspecified number of executives, claiming to have stolen sensitive data from their Oracle business applications, Reuters reported.
In a statement, Google said a group claiming affiliation with the ransomware gang cl0p was sending emails to "executives at numerous organizations claiming to have stolen sensitive data from their Oracle E-Business Suite."
Google cautioned that it "does not currently have sufficient evidence to assess the veracity of these claims definitively."
Messages seeking comment from cl0p and Oracle were not immediately returned. Google described the email campaign as "high-volume" but declined to share further details.
What is cl0p?
Cl0p is a cybercriminal group notorious for targeting major corporations using advanced malware designed to encrypt files and demand ransoms for their release or deletion. In 2023, Cl0p was implicated in a widespread cyberattack exploiting vulnerabilities in MOVEit — a file transfer software widely used by companies and institutions to handle sensitive data.
The group claimed to have accessed data from hundreds of organizations through this exploit.
Prominent victims of the attack included Shell Plc, IAG SA’s British Airways, and the BBC.
In June 2023, the US Cybersecurity and Infrastructure Security Agency (CISA) issued a public advisory warning about Cl0p, describing it as "one of the largest distributors of phishing and malspam globally." The agency estimated that the group had breached over 3,000 organizations in the United States and more than 8,000 worldwide.
With input from wires.