Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Bimbo Bakeries USA, the American arm of the world’s largest baking company, has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS), joining a growing list of organizations swept up in the Clop ransomware gang’s global extortion campaign against Oracle customers.

In a notification letter dated August 31, 2026, and filed with the California Attorney General’s office on September 4, as detailed in the official filing published by the California Attorney General’s Office, the bakery giant said the incident traced back to a third-party vendor that relied on Oracle EBS.

Bimbo Oracle EBS Data Breach

The company disclosed that its investigation determined on December 6, 2025, that attackers had exploited the zero-day to acquire files stored within the platform.

Bimbo Bakeries said it applied Oracle’s emergency patches as soon as it learned of the flaw and launched a forensic review to determine exactly what data had been exposed.

That review took months to complete. It wasn’t until August 19, 2026, that the company confirmed one of the stolen files contained victims’ names and Social Security numbers, triggering the formal notification process required under state breach-disclosure laws.

While Bimbo Bakeries’ letter doesn’t name the specific flaw, the timeline and vendor match a widely documented campaign tied to CVE-2025-61882, a critical unauthenticated remote code execution vulnerability in the BI Publisher Integration component of Oracle EBS’s Concurrent Processing module.

Rated 9.8 on the CVSS scale, the bug let attackers run arbitrary code on unpatched EBS servers without needing valid credentials. Google-owned Mandiant traced exploitation back to August 2025, weeks before Oracle issued an emergency patch on October 4, 2025.

Researchers attributed the campaign to the Clop extortion group, which used the flaw to steal data from numerous Oracle EBS customers, including Harvard University and The Washington Post, before pressuring victims with ransom demands.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog shortly after Oracle’s disclosure. Bimbo Bakeries has not publicly attributed the breach to Clop, disclosed how many individuals were affected, or confirmed whether it received an extortion demand.

Bimbo Bakeries said it is “re-evaluating its vendor relationships” following the incident and is offering affected individuals 12 months of free single-bureau credit monitoring and fraud assistance through Cyberscout.

Security experts continue urging any organization still running Oracle EBS versions 12.2.3 through 12.2.14 to confirm the October 2025 emergency patch is applied, audit logs for suspicious BI Publisher activity dating back to mid-2025, and rotate credentials tied to EBS integrations.

Given the sensitivity of stolen data, affected individuals should monitor credit reports, enable fraud alerts, and remain wary of phishing attempts referencing the breach.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack appeared first on Cyber Security News.