Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Bimbo Bakeries Employee Data Stolen Through Oracle EBS Zero-Day
Bimbo Bakeries Employee Data Stolen Through Oracle EBS Zero-Day
Read Time:3 Minute, 8 Second

Bimbo Bakeries USA has confirmed that employee information was stolen after attackers compromised an Oracle E-Business Suite environment operated by a third-party vendor. The incident adds the US business of the global baking company to the growing roster of organizations affected by a campaign targeting a critical Oracle enterprise software weakness.

According to a breach notification dated August 31 and filed with California authorities on September 4, the attackers obtained files held in the vendor’s platform. Bimbo Bakeries determined on December 6, 2025 that exploitation had occurred, but the lengthy review of the affected material did not establish until August 19, 2026 that a stolen file contained names and Social Security numbers.

A critical flaw at the center of a wider campaign

The company’s notification does not identify a vulnerability by number. However, the timing and affected product align with the campaign involving CVE-2025-61882, a critical flaw in the BI Publisher Integration component of Oracle E-Business Suite. The weakness carries a CVSS score of 9.8 and can allow unauthenticated attackers to execute code on vulnerable servers.

Researchers tracked exploitation to August 2025, before Oracle issued an emergency security update on October 4. The gap between initial attacks and public remediation gave intruders an opportunity to search exposed environments, collect business data and prepare extortion demands. The US Cybersecurity and Infrastructure Security Agency later placed the flaw in its Known Exploited Vulnerabilities catalog.

The broader activity has been associated with the Clop extortion operation, whose campaigns typically focus on stealing files at scale and then pressuring organizations to pay. Other Oracle EBS customers were also affected. Bimbo Bakeries has not publicly attributed its own incident to Clop, said whether it received a demand, or disclosed the number of individuals whose information was exposed.

Third-party exposure complicates the response

The breach illustrates how a supplier’s enterprise application can become part of a company’s risk perimeter. Even when the affected system is not operated directly by the organization named in a notification, the customer remains responsible for understanding what information a provider holds, how quickly vulnerabilities are handled, and whether compromise checks occur after patches are installed.

Bimbo Bakeries said it applied Oracle’s emergency updates after learning of the vulnerability and began a forensic investigation. It is also reassessing vendor relationships. Affected individuals are being offered 12 months of single-bureau credit monitoring and fraud assistance through Cyberscout.

Actions for Oracle EBS operators

Organizations using Oracle EBS versions 12.2.3 through 12.2.14 should confirm that the emergency update is present and should not treat patch installation alone as proof that an environment is clean. Investigation should extend to the period before disclosure, when exploitation may already have been underway.

  • Review BI Publisher and web access records for unusual requests dating to mid-2025.
  • Identify unexpected file access, exports and outbound transfers from EBS systems.
  • Rotate credentials used by integrations and accounts with access to sensitive records.
  • Validate that vendors followed both the patching and compromise-assessment guidance.
  • Preserve evidence and involve incident responders if suspicious activity is found.

What affected employees should watch for

Names combined with Social Security numbers can support identity fraud long after the original breach. Recipients should activate the offered monitoring, review credit reports, consider a fraud alert or credit freeze, and verify messages that claim to concern the incident. Attackers frequently use public breach reports to make follow-on phishing more believable.

The delayed confirmation also shows why data discovery matters during incident response. Establishing that attackers reached a system is only the first step; organizations need reliable inventories and retention policies so they can quickly determine whose records were present and deliver useful notices without months of uncertainty.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Bimbo Bakeries Employee Data Stolen Through Oracle EBS Zero-Day, use the discussion on Forum.

>> forum community

Comments

Leave a Reply