Technology

Cox Enterprises hit by Oracle data breach - but it won't name who carried out the attack

2025-11-24 16:03
975 views
Cox Enterprises hit by Oracle data breach - but it won't name who carried out the attack

Cl0p ransomware group says it has already leaked the stolen files on the dark web.

  1. Pro
  2. Security
Cox Enterprises hit by Oracle data breach - but it won't name who carried out the attack News By Sead Fadilpašić published 24 November 2025

Has Cl0p struck again?

Comments (0) ()

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Data breach (Image credit: Shutterstock)
  • Cox Enterprises breached via Oracle E-Business Suite zero‑day, exposing data of 9,479 individuals
  • Cl0p ransomware group claimed responsibility, publishing stolen files on its leak site in late October
  • Cox offers 24 months of free credit monitoring and identity theft protection to affected victims

Cox Enterprises, an American global conglomerate with major subsidiaries in telecommunications and automotive services, has confirmed being the latest in the long line of companies compromised through a zero-day in the Oracle E-Business Suite.

The company filed a new report with the Maine Attorney General’s Office, stating that it was breached in August, but only spotted the intrusion in late September, 2025, along with a data breach notification letter sent out to affected individuals - exactly 9,479 people.

  • Amazon Black Friday deals are live: here are our picks!

“Unfortunately, this issue affected many companies that use Oracle’s systems, including Cox,” it said. “Once we learned of this activity, we promptly launched an investigation and applied Oracle’s security fix as soon as it became available. We also brought in cybersecurity experts and data analysts to review our systems and the data that we thought may have been copied and taken. We have also been in contact with law enforcement.”

You may like
  • A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted." Google researchers say Oracle EBR hackers have hit dozens of organizations
  • Lock on Laptop Screen The Washington Post confirms it suffered an Oracle-linked data breach
  • Password recovery concept image showing man typing on a keyboard with an overlay imitating password recovery and data recovery principles GlobalLogic says data on 10,000 workers exposed in Oracle-linked data breach

Files pop up on the dark web

The investigation, which concluded on October 31, 2025, determined the hackers stole personal information, including full names - however other details about the nature of the files were redacted from the data breach notification letter.

Cox did not name the perpetrators, but from previous reports we know that the ransomware group known as Cl0p was behind the Oracle attacks.

The conglomerate is not the first company to have been struck through Oracle, with Logitech, Washington Post, GlobalLogic, Envoy Air, and Harvard University being just some of the high-profile names being mentioned.

Cl0p added Cox Enterprise to its data leak website on October 27, and has already published the stolen information.

Are you a pro? Subscribe to our newsletterContact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsorsBy submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

To mitigate the risk, Cox is offering up to 24 months of free credit monitoring and identity theft protection services through IDX for all affected individuals.

Via BleepingComputer

Best antivirus software headerThe best antivirus for all budgetsOur top picks, based on real-world testing and comparisons

➡️ Read our full guide to the best antivirus1. Best overall:Bitdefender Total Security2. Best for families:Norton 360 with LifeLock3. Best for mobile:McAfee Mobile Security

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Sead FadilpašićSocial Links Navigation

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Logout Read more A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted." Google researchers say Oracle EBR hackers have hit dozens of organizations    Lock on Laptop Screen The Washington Post confirms it suffered an Oracle-linked data breach    Password recovery concept image showing man typing on a keyboard with an overlay imitating password recovery and data recovery principles GlobalLogic says data on 10,000 workers exposed in Oracle-linked data breach    Ransomware hackers claim Oracle app breach, tell victims their data has been stolen    hacker hands at work with interface around Logitech confirms data breach - but says it isn't sure exactly what information was lost    Data leak Over 120 million Reputation.com records might have leaked online - here's what we know    Latest in Security airplane Iberia tells customers it was hit by a major security breach    Hands on a laptop with overlaid logos representing network security Google security experts say Gainsight hacks may have left hundreds of companies affected    Comet Browser AI Perplexity responds to Comet browser vulnerability claims, argues "fake news"    cables going into the back of a broadband router on white background D-Link routers under threat from dangerous flaw - here's how to stay safe    A representational concept of a social media network Second-order prompt injection can turn AI into a malicious insider    A person holding a phone looking at a text with warning signs Too good to be true? Be careful when looking through those Black Friday offers - they might be a scam    Latest in News OnePlus Watch 3 OnePlus just dropped its own Apple Watch SE rival with the affordable Watch Lite    Bigg Boss 19 eye logo How to watch Bigg Boss 19 online for *FREE*    Power button of Steam Machine Valve dashes dreams of $500 Steam Machine with new hint on pricing    The OnePlus 15R, OnePlus Pad Go 2, and OnePlus Watch Lite OnePlus 15R launch date confirmed – and it's arriving alongside two other devices    Data breach Cox Enterprises hit by Oracle data breach - but it won't name who carried out the attack    DJI Neo in flight in front of trees DJI explains what its looming US ban means for your drones    LATEST ARTICLES