Site icon BW Security World

Harvard Confirmed As First Victim In Major Data Theft

Cybercriminals exploit E-Business Suite vulnerability to steal over 1.3TB of data; attack linked to notorious Cl0p and FIN11 threat groups

Harvard University has been identified as the first confirmed high-profile victim in a significant cybercrime campaign targeting global customers of Oracle’s E-Business Suite (EBS) solution. The attack, which leverages vulnerabilities in the administrative software, resulted in a listing on the data leak website operated by the Cl0p ransomware syndicate on October 12.

Following initial naming, the cybercriminals have now published a link claiming to hold over 1.3 terabytes (TB) of archived data allegedly stolen from the institution. While the exact contents of the leaked files remain unverified, the sheer volume points to a substantial intrusion.

In a confirming statement, Harvard acknowledged the targeting as part of the wider Oracle EBS campaign. The university’s ongoing investigation suggests the incident impacts “a limited number of parties associated with a small administrative unit.” Harvard further stated that the exploited vulnerability has been patched and that there is currently no evidence of compromise to other, separate internal systems.

Dozens Of Organisations Targeted

Security experts believe the threat landscape is much broader. Google’s Threat Intelligence Group (GTIG) and Mandiant estimate that dozens of organisations globally have been targeted in the coordinated campaign. Given that EBS instances typically manage core enterprise functions, the sensitivity of the exposed information is critically high, potentially including financial, customer, supplier, human resources, and inventory data.

The attackers used extortion emails sent to corporate executives on behalf of the Cl0p ransomware group—a tactic likely deployed to leverage the group’s reputation for successful, large-scale data theft. Cl0p has been tied to highly damaging campaigns in recent years that exploited file transfer products from vendors like MOVEit, Fortra, Cleo, and Accellion.

Linking Threat Actors

While a formal attribution for the Oracle attack is pending, GTIG and Mandiant have identified several connections to the cybercrime group tracked as FIN11. This group has historically operated alongside Cl0p in previous mass-exploitation events against technology platforms.

The attacks on Oracle EBS customers are understood to have involved the sophisticated deployment of malware and the exploitation of both known and zero-day vulnerabilities within the software suite. CrowdStrike reported that active exploitation of the flaws appeared to have begun around August 9, though intelligence gathered by Google indicates the initial attacks may have started as early as July 10, suggesting a long period of vulnerability prior to the public disclosure of the breaches.

Exit mobile version