CyberSecurity SEE

Bimbo Bakeries USA Data Breach Leaks SSNs in Oracle E-Business Suite Zero-Day Attack

Bimbo Bakeries USA Data Breach Leaks SSNs in Oracle E-Business Suite Zero-Day Attack

Bimbo Bakeries USA Suffers Data Breach Linked to Oracle Vulnerability

Bimbo Bakeries USA (BBU) has disclosed a significant data breach following the exploitation of a zero-day vulnerability in Oracle E-Business Suite (EBS), a platform utilized by one of its third-party vendors. The breach allowed unauthorized individuals to gain access to files containing sensitive information, including names and Social Security numbers.

The company first reported the unauthorized access in December 2025. However, it was not until August 2026 that BBU confirmed the existence of Social Security numbers within the compromised files, raising concerns over the potential for identity theft among those affected.

In notices dated August 31, 2026, BBU stated that after becoming aware of the zero-day vulnerability, it swiftly applied the patches provided by Oracle and launched an investigation into the incident. This investigative process, which concluded on December 6, 2025, confirmed that unauthorized parties successfully obtained files housed within the compromised Oracle EBS application. Following the investigation, BBU undertook a thorough review of the files to ascertain their contents.

On August 19, 2026, the review revealed troubling findings: a file containing the names and Social Security numbers of individuals affected by the breach. Nevertheless, BBU has refrained from disclosing essential details such as the number of individuals impacted, the extent of the compromised data, the specific initial access point exploited by the attackers, or whether the breach extended beyond the EBS environment.

Furthermore, the company has not attributed the intrusion to any specific cybercriminal group, nor has it indicated whether it received any demands for extortion in connection with the breach. This lack of transparency raises questions regarding the potential threat landscape surrounding BBU and the protective measures they have in place.

In response to the incident, BBU is reevaluating its relationships with its vendors to ensure greater security protocols moving forward. To mitigate potential damage to those impacted by the data breach, the company has taken the proactive step of offering affected individuals a complimentary 12 months of credit monitoring services through Cyberscout. This initiative includes credit reports, credit score services, and fraud assistance, aiming to help individuals safeguard their financial identities.

Moreover, BBU’s notification encourages affected individuals to take a proactive approach by reviewing their account activity and credit reports. They provided detailed guidance on setting up fraud alerts and placing security freezes to thwart potential identity theft.

While BBU’s notification did not specify a Common Vulnerabilities and Exposures (CVE) number, the timeline and nature of the breach align with the Oracle EBS campaign linked to CVE-2025-61882. An emergency patch issued by Oracle in October 2025 addressed a critical flaw within the EBS software affecting versions 12.2.3 to 12.2.14. This vulnerability allowed for unauthenticated remote code execution, heightening the risks associated with unauthorized data access.

The Google Threat Intelligence Group (GTIG) has indicated that the exploitation of this vulnerability likely commenced in August 2025, before the patch was made available. Researchers later identified a large-scale extortion operation linked to the group known as CL0P. However, experts caution that the mere branding of an operation does not provide definitive attribution to any specific group. BBU has not confirmed any direct association with CL0P, leaving the situation ambiguous.

GTIG noted that exploitation took place through a POST request to /OA_HTML/SyncServlet, leading to the creation and execution of a malicious EBS database template. For those involved in Oracle EBS operations, GTIG has advised that patching alone does not constitute complete remediation. It is paramount for organizations to verify that emergency fixes and prerequisite Critical Patch Updates are fully installed.

Additionally, operators are urged to investigate historical logs for SyncServlet, UiServlet, and TemplatePreviewPG requests, while also reviewing the XDO_TEMPLATES_B and XDO_LOBS for any unusual templates. Restricting unnecessary internet access from EBS servers can help minimize the risk of payload retrieval and data exfiltration.

This incident serves as a significant reminder of the vulnerabilities associated with third-party platforms that house sensitive workforce data. Organizations are encouraged to conduct thorough inventories of vendor-hosted EBS deployments, implement stringent log retention and forensic access protocols, and effectively test their incident notification processes to prepare for any future breaches.

Source link

Exit mobile version