Bimbo Bakeries USA, a prominent entity in the global baking industry, has confirmed that a cyberattack led to the unauthorized access of employee data. This breach was facilitated through a zero-day vulnerability in Oracle’s E-Business Suite (EBS), putting Bimbo Bakeries among several organizations targeted by the Clop ransomware group.
Details of the Breach
On August 31, 2026, Bimbo Bakeries notified affected parties in a letter submitted to the California Attorney General. The breach is linked to a third-party vendor utilizing Oracle EBS, as noted in the official records with the Attorney General’s Office.
The bakery giant discovered on December 6, 2025, that hackers had exploited this vulnerability to access files within the platform. Immediate action was taken to apply Oracle’s emergency patches, followed by a forensic investigation to assess the data exposure.
Timeline and Vulnerability
After months of investigation, it was confirmed on August 19, 2026, that personal information, including names and Social Security numbers, was compromised. This finding initiated the formal notification process required by state laws.
While Bimbo Bakeries has not specified the exact flaw, the details align with a campaign associated with CVE-2025-61882. This critical vulnerability allowed attackers to execute code on EBS servers without credentials, rated 9.8 on the CVSS scale.
Google’s Mandiant traced the breach back to August 2025, preceding Oracle’s patch release on October 4, 2025. The Clop group exploited this flaw to steal data from several Oracle EBS users, including high-profile institutions.
Response and Recommendations
Bimbo Bakeries has not officially linked the attack to the Clop group, nor disclosed the number of individuals affected or any ransom demands received. The company is reassessing its vendor partnerships and offering affected employees a year of credit monitoring and fraud protection through Cyberscout.
Security specialists advise organizations using Oracle EBS versions 12.2.3 to 12.2.14 to ensure the October 2025 patch is implemented. They should also review logs for unusual BI Publisher activities and update credentials related to EBS integrations.
Given the sensitivity of the compromised data, affected individuals are urged to keep a close watch on their credit reports, activate fraud alerts, and be cautious of phishing attempts using the breach as a pretext.
