# Four Major Companies Remain Silent on Oracle EBS Hack

**Published:** 2026-06-11T21:12:34.212Z  
**Topic:** Oracle warns of security bug that hackers abused to breach 100+ companies  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/171527b6-31c6-4549-8400-7e6fba9d90cc

Major firms Broadcom, Bechtel, Estée Lauder and Abbott have not commented on the Oracle E‑Business Suite breach that Cl0p claims affected dozens of

The Cl0p ransomware group has publicly linked a large‑scale data‑exfiltration campaign to Oracle’s E‑Business Suite (EBS) software, naming over 100 victims across multiple sectors [1]. Among the most prominent organizations listed, four corporate giants—Broadcom, Bechtel, Estée Lauder Companies and Abbott Laboratories—have not issued any public comment or confirmation of an investigation [1].

**Key takeaways**  
- Cl0p claims to have stolen terabytes of data from the four silent firms, with more than 2 TB allegedly from Broadcom and 870 GB from Estée Lauder [1].  
- The campaign exploits zero‑day vulnerabilities in Oracle EBS, a flaw first patched by Oracle on Oct. 4, 2025 [2][4].  
- Several high‑profile victims, including the University of Phoenix and The Washington Post, have confirmed breaches or are under investigation [2][3].  
- Analysts suggest the extortion emails may be a pressure tactic, and the true scale of the breach remains unverified [4].  

## Silent giants and the data claimed to be leaked  

The Cl0p leak site lists Broadcom, a semiconductor and infrastructure software company, as having more than 2 TB of archive files attributed to it [1]. Estée Lauder’s entry points to 870 GB of data, while torrents for Bechtel and Abbott remain accessible, though no files have been retrieved for analysis [1]. SecurityWeek’s metadata review confirmed that the file structures match an Oracle EBS environment, but the organization has not downloaded the data itself [1].  

The lack of statements from these firms contrasts with the broader pattern of public disclosures. Many affected organizations have issued breach notices, often emphasizing limited impact and offering identity‑protection services, as seen with the University of Phoenix, which reported exposure of names, Social Security numbers and bank details for millions of students and staff [2]. The Washington Post also confirmed a breach linked to the same Oracle vulnerabilities [3].  

## Extortion tactics and uncertainty over breach scope  

Cl0p’s strategy involves sending extortion emails that claim the theft of financial and operational data from Oracle EBS, demanding payments that can reach up to $50 million [4]. The emails provide proof of compromise, such as file‑tree listings, but security researchers note that no concrete evidence of the alleged data volume has been published [4]. Oracle has acknowledged awareness of the extortion messages and is assisting customers, yet it has not confirmed any data theft [4].  

Analysts warn that the campaign could be a bluff designed to extract payments, noting that ransomware groups often exaggerate breach scope to pressure victims [1]. The silence of Broadcom, Bechtel, Estée Lauder and Abbott may stem from strategic, legal or reputational considerations, as acknowledging an investigation could invite lawsuits or regulatory scrutiny [1].  

## Why it matters  

The ongoing Oracle EBS hack highlights the risks of unpatched enterprise software and the challenges of attribution in multi‑actor cyber campaigns. As more organizations discover the extent of the breach, regulators may scrutinize disclosure practices, especially when personal data such as Social Security numbers is involved. The four silent firms’ eventual response—whether a denial, confirmation or remediation plan—will shape stakeholder expectations for transparency in large‑scale cyber incidents.

## Sources
1. Securityweek — [Oracle EBS Hack: Only 4 Corporate Giants Still Silent on](https://www.securityweek.com/oracle-ebs-hack-only-4-corporate-giants-still-silent-on-potential-impact/)
2. Government Technology — [Oracle Hack Impacts 3.5M Associated With University of Phoenix](https://www.govtech.com/education/higher-ed/oracle-hack-impacts-3-5m-associated-with-university-of-phoenix)
3. TechCrunch — [Washington Post confirms data breach linked to Oracle hacks](https://techcrunch.com/2025/11/07/washington-post-confirms-data-breach-linked-to-oracle-hacks/)
4. SiliconANGLE — [Clop-linked hackers claim Oracle E-Business Suite data theft in high-stakes extortion push](https://siliconangle.com/2025/10/02/clop-linked-hackers-claim-oracle-e-business-suite-data-theft-high-stakes-extortion-push/)

---
Cite as: TrendWatcher, "Four Major Companies Remain Silent on Oracle EBS Hack", https://www.trendwatcher.in/article/171527b6-31c6-4549-8400-7e6fba9d90cc
