Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationactively-exploited-vulnerabilityinternet-facing-service-vulnerabilitywidely-deployed-product-advisory

Envoy Air Data Breach via Oracle E-Business Suite Zero-Day Exploitation

Updated 3mo agoFirst seen Oct 22, 20252 sources

Envoy Air, a major regional airline operating under American Airlines, experienced a significant data breach in October 2025 following a sophisticated ransomware attack. The breach was traced to the exploitation of a zero-day vulnerability, CVE-2025-61882, in Oracle’s E-Business Suite (EBS), which allowed unauthenticated remote code execution on unpatched systems. The Clop ransomware group, known for targeting large organizations, weaponized this vulnerability as part of a broader campaign affecting multiple industries worldwide. The attack campaign began in August 2025 and escalated through September, prompting Oracle to issue an emergency patch in early October. Envoy Air’s investigation revealed that approximately 26GB of internal business documents and commercial contacts were exfiltrated and later published on Clop’s leak site. However, the airline confirmed that no sensitive customer personally identifiable information (PII), loyalty program data, or flight operations systems were compromised. The breach was contained to non-operational, non-customer-facing IT assets, as corroborated by independent monitors and incident response teams. The incident highlighted the systemic risk posed by widespread adoption of enterprise resource planning (ERP) platforms like Oracle EBS, as other victims included higher education institutions and multinational corporations. Oracle’s October 2025 Critical Patch Update addressed 170 unique CVEs across 29 product families, with 20 patches specifically for Oracle EBS, including fixes for vulnerabilities that could be exploited remotely without authentication. The update included critical patches for multiple Oracle products, reflecting the urgency and severity of the vulnerabilities exploited in the campaign. Envoy Air worked closely with cybersecurity experts and law enforcement to contain the breach and implement remediation measures. The incident underscored the importance of timely patch management and the risks associated with unpatched enterprise software. The Clop group’s use of a zero-day exploit demonstrated the evolving tactics of ransomware operators targeting high-value enterprise systems. The breach also prompted industry-wide reviews of Oracle EBS deployments and accelerated the adoption of security best practices. Oracle’s rapid response and emergency patch release were crucial in mitigating further exploitation. The event serves as a cautionary tale for organizations relying on complex ERP platforms, emphasizing the need for proactive vulnerability management. The breach’s limited impact on customer-facing systems was attributed to effective network segmentation and incident response protocols. The campaign’s global reach highlighted the interconnected nature of modern enterprise IT environments and the potential for cascading risks.

Share:
Envoy Air Data Breach via Oracle E-Business Suite Zero-Day Exploitation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Oct 21, 20258mo ago

Envoy Air data breach is publicly reported

A data breach affecting Envoy Air was publicly reported in the referenced coverage. No additional incident details or earlier milestones are provided in the available content.

Oracle releases October 2025 Critical Patch Update for 170 CVEs

Oracle issued its October 2025 Critical Patch Update addressing 170 vulnerabilities across its products. This patch release is the key disclosed event referenced in the source material.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Envoy Air Data Breach via Oracle E-Business Suite Zero-Day Exploitation | Mallory