Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Linux Rootkit Injects Fileless PHP Web Shells on F5 BIG-IP Servers
September 7, 2026
Bimbo Bakeries USA Confirms Data Breach After Oracle EBS Zero-Day Attack
September 7, 2026
Mathspace Data Breach Exposes 1 Million Users’ Personal Info
September 7, 2026
Home/CyberSecurity News/Bimbo Bakeries USA Confirms Data Breach After Oracle EBS Zero-Day Attack
CyberSecurity News

Bimbo Bakeries USA Confirms Data Breach After Oracle EBS Zero-Day Attack

Key Takeaways Bimbo Bakeries USA confirmed a data breach stemming from a zero-day exploit in Oracle’s E-Business Suite (EBS). Employee names and Social Security numbers were stolen due to a...

Marcus Rodriguez
Marcus Rodriguez
September 7, 2026 3 Min Read
2 0

Key Takeaways

  • Bimbo Bakeries USA confirmed a data breach stemming from a zero-day exploit in Oracle’s E-Business Suite (EBS).
  • Employee names and Social Security numbers were stolen due to a vulnerability in a third-party vendor’s Oracle EBS instance.
  • The attack is linked to CVE-2025-61882, a critical remote code execution flaw with a CVSS score of 9.8, exploited by the Clop ransomware group.
  • Oracle issued an emergency patch for the vulnerability on October 4, 2025, weeks after initial exploitation was detected.

Bimbo Bakeries USA, the U.S. division of the world’s largest baking conglomerate, has officially acknowledged a data breach. The incident involved the theft of employee information, orchestrated by hackers who leveraged a zero-day vulnerability within Oracle’s E-Business Suite (EBS). This attack places Bimbo Bakeries among a growing list of organizations targeted by the Clop ransomware gang’s extensive extortion campaign against Oracle customers worldwide.

Table Of Content

  • Key Takeaways
  • Oracle EBS Vulnerability Exploited
  • Discovery and Disclosure Timeline
  • The Critical Flaw: CVE-2025-61882
  • Company Response and Mitigation
  • What You Should Do

A notification letter, dated August 31, 2026, and submitted to the California Attorney General’s Office on September 4, confirmed the breach. The bakery giant indicated that the compromise originated with a third-party vendor utilizing Oracle EBS.

Oracle EBS Vulnerability Exploited

Discovery and Disclosure Timeline

The company’s investigation, concluded on December 6, 2025, determined that attackers had successfully exploited the zero-day flaw to exfiltrate files from the platform. Bimbo Bakeries stated it promptly applied Oracle’s emergency patches upon learning of the vulnerability and initiated a comprehensive forensic review to ascertain the precise scope of data exposure.

The forensic analysis was a multi-month endeavor. It wasn’t until August 19, 2026, that the company definitively confirmed that one of the compromised files contained the names and Social Security numbers of affected individuals. This confirmation triggered the formal notification procedures mandated by state breach-disclosure regulations.

The Critical Flaw: CVE-2025-61882

Although Bimbo Bakeries’ official communication does not explicitly name the vulnerability, the timeline and the involvement of a vendor align with details surrounding CVE-2025-61882. This critical unauthenticated remote code execution vulnerability affects the BI Publisher Integration component within Oracle EBS’s Concurrent Processing module. With a CVSS score of 9.8, this flaw allowed attackers to execute arbitrary code on vulnerable EBS servers without requiring any authentication credentials.

Mandiant, a cybersecurity firm owned by Google, tracked exploitation of this vulnerability back to August 2025, several weeks before Oracle released an emergency patch on October 4, 2025. Researchers have attributed the campaign exploiting this flaw to the Clop extortion group, which has used it to steal data from numerous Oracle EBS clients, including prominent institutions like Harvard University and The Washington Post, subsequently demanding ransom payments.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-61882 to its Known Exploited Vulnerabilities catalog shortly after Oracle’s public disclosure. While Bimbo Bakeries has not publicly linked the breach to Clop, disclosed the exact number of affected individuals, or confirmed any extortion demands, the circumstances strongly suggest a connection.

Company Response and Mitigation

In the wake of the incident, Bimbo Bakeries announced it is “re-evaluating its vendor relationships.” To support affected individuals, the company is providing 12 months of complimentary single-bureau credit monitoring and fraud assistance through Cyberscout.

What You Should Do

  • Organizations running Oracle EBS versions 12.2.3 through 12.2.14 must verify that the October 2025 emergency patch for CVE-2025-61882 is fully applied.
  • Conduct thorough audits of logs for any suspicious activity related to BI Publisher, particularly dating back to mid-2025.
  • Immediately rotate all credentials associated with EBS integrations.
  • Affected individuals should proactively monitor credit reports, enable fraud alerts with credit bureaus, and exercise extreme caution regarding any unsolicited communications, particularly phishing attempts that reference the data breach.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachCVEExploitHackerPatchphishingransomwareSecurityVulnerabilityzero-day

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Mathspace Data Breach Exposes 1 Million Users’ Personal Info

Next Post

Linux Rootkit Injects Fileless PHP Web Shells on F5 BIG-IP Servers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Ends Manifest V2 Extension Support, Shifts to More Secure V3
September 7, 2026
Natural Resources Wales Exposes Sensitive Employee Data
September 7, 2026
ConnectWise Patches Critical ScreenConnect Vulnerability CVE-2024-46805
September 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us