Saturday, October 4, 2025
spot_img

Google Flags Surge in Extortion Emails Sent to Executives

spot_img
- Advertisement -

Google has issued a warning about a surge in extortion emails being sent to executives at large organizations.

The tech company revealed that a group claiming affiliation with the Clop ransomware gang is behind the campaign, which began around September 29, 2025.

The senders of these emails allege that they have stolen sensitive data from Oracle’s E-Business Suite, a widely used enterprise resource planning platform.

The attackers are demanding ransom payments in exchange for not releasing the purported data.

Google emphasized that it has not yet verified the authenticity of the claims and is continuing to investigate the scope and impact of the campaign.

Emails Sent from Compromised Accounts to Google Executives

Google’s incident response unit Mandiant reported that hackers are sending extortion emails from hundreds of compromised accounts.

At least one of these accounts has previously been linked to FIN11, a financially motivated threat group associated with Clop.

Hackers reportedly include contact details listed on Clop’s data leak site in the emails, often using the site to pressure victims into paying ransoms to prevent public disclosure of stolen files.

Charles Carmakal, Chief Technology Officer at Mandiant, noted that the campaign is high-volume and appears to be well-coordinated.

Hackers are directing the emails at executives and IT leaders, increasing the psychological pressure on organizations to respond quickly.

Exploiting Oracle E-Business Suite Vulnerabilities

The attackers claim to have exploited vulnerabilities in Oracle’s E-Business Suite to gain access to sensitive corporate data.

Bloomberg reported that the hackers used compromised user emails to initiate access attempts.

They then abused the default password-reset function to obtain working credentials for Oracle web portals accessible from the internet.

Thousands of companies worldwide use Oracle’s E-Business Suite as a critical system to manage customer databases, employee records, and financial operations.

While Oracle has not commented publicly on the breach, the platform’s importance makes it a high-value target for cybercriminals.

Ransom Demands Reach Tens of Millions

Cybersecurity firm Halcyon is assisting in the response to the campaign. It reported that ransom demands range from millions to tens of millions of dollars.

In one case, the demand reached $50 million.

Cynthia Kaiser, head of Halcyon’s Ransomware Research Center, noted that while the Clop connection is plausible, there is overlap among various ransomware groups and copycat actors, making attribution complex.

Google stated that it currently lacks sufficient evidence to confirm whether any data was actually stolen.

The company is urging organizations to remain vigilant and to review their security protocols, especially those related to Oracle systems.


Note: We are also on WhatsApp, LinkedIn, and YouTube to get the latest news updates. Subscribe to our Channels. WhatsApp– Click HereYouTube â€“ Click Here, and LinkedIn– Click Here.

spot_img

Editorial

Why TCS Deferred FY25 Salary Hike: Better Hike Ahead?

TCS had initially announced its annual salary hike during...

Deloitte, PWC, EY, KPMG to Hire 1 Lakh People in India in FY25

According to estimates from top company officials and industry...

Higher EPS Pension Application Stuck: A Step-by-Step Guide to Fix

Nearly 97,640 Provident Fund (PF) members and pensioners under...

Employee Benefits at India’s Big 4 Firms Deloitte, PwC , EY, KPMG

The Big 4 firms; Deloitte, PwC (PricewaterhouseCoopers), EY (Ernst...

TCS Announces 4-8% Salary Hike for FY25, Lowest in Last 4 Years

Tata Consultancy Services (TCS), India's largest IT services provider,...

Must Read

LIC and EPFO keen to set up fund for startups, says DPIIT official

LIC (Life Insurance Corporation of India) and Employees' Provident...

Hardly 10% of employees have returned back to office, Report

Hardly 10% of employees have returned back to office,...

Flipkart recruitment drive for various hybrid, WFO, WFA jobs; Apply

An Indian e-commerce company, Flipkart is hiring for various...

The Sleep Company Ropes-in Kamaljeet Singh as CHRO

The Sleep Company (TSC), a leading manufacturer of SmartGRID...

EPFO has credited 8.5% interest in 22.55 crore account holders for FY21

Employees’ Provident Fund Organisation (EPFO) has credited an interest...

SIRO becomes the first CRO in India to introduce a hybrid working model

SIRO Clinpharm, an end-to-end drug development solutions provider to...

McAfee Welcomes Justin Hastings as Chief People Officer

McAfee, a global leader in online protection, has made...

Robots say they won’t steal jobs: AI press conference

Robots presented at an AI press conference said that...

Related Articles

Sahiba Sharma
Sahiba Sharmahttps://sightsinplus.com/
Sahiba Sharma, Senior Editor - Content at SightsIn Plus