Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

American Airlines Subsidiary Envoy Air Hit by Oracle Hack

Posted on October 20, 2025October 20, 2025 By CWS

American Airways subsidiary Envoy Air has confirmed being impacted by the current cybercrime marketing campaign concentrating on organizations that use Oracle’s E-Enterprise Suite (EBS) enterprise administration resolution. 

American Airways was listed late final week on the Tor-based leak web site of the Cl0p ransomware group. The Oracle EBS marketing campaign has been claimed within the identify of Cl0p and it has been linked to a cybercrime group generally known as FIN11.

On the time of writing, the cybercriminals have made public the allegedly stolen American Airways information, which totals greater than 26 GB of archive recordsdata. 

Whereas the hackers named American Airways on their leak web site, it seems that in actuality they focused an Oracle EBS occasion utilized by Envoy Air.

Texas-based Envoy Air describes itself as the most important regional service for American Airways, with over 800 every day flights to greater than 160 locations beneath the American Eagle model.  

In a press release to the media, Envoy confirmed being impacted by the Oracle EBS marketing campaign, however the firm stated its investigation has proven that buyer or different delicate information was not compromised. 

Envoy admitted that “a restricted quantity of enterprise info and industrial contact particulars could have been compromised”.

Harvard College was the primary confirmed sufferer of the Oracle EBS hack. Different organizations have since been listed on the Cl0p leak web site, together with South Africa’s College of the Witwatersrand, Johannesburg.Commercial. Scroll to proceed studying.

The South African college confirmed in a press release posted on its web site that it has been focused, and stated it’s engaged on figuring out what information was compromised because of the assault. The hackers have already made public the recordsdata allegedly stolen from the College of the Witwatersrand.

The Cl0p web site additionally lists industrial large Emerson, however no information has been leaked on the time of writing. SecurityWeek has reached out to Emerson for remark. 

Dozens of victims of the Oracle EBS marketing campaign have acquired extortion emails from the attackers. The organizations that at the moment are being listed on the Cl0p web site are probably people who have refused to pay a ransom. 

Whereas the Oracle marketing campaign has been linked to Cl0p and FIN11, it’s value mentioning that Google’s Mandiant tracks a number of menace clusters beneath the FIN11 umbrella, and it’s unclear precisely which cluster is behind the assault.

It’s additionally unclear which Oracle EBS vulnerabilities have been exploited within the assault. Oracle initially stated identified flaws patched in July have been concerned, and later introduced patches for a zero-day (CVE-2025-61882) apparently exploited within the marketing campaign. The software program large has additionally mounted CVE-2025-61884, one other EBS flaw exposing delicate information, however has not clarified whether or not it has additionally been exploited.  

Associated: F5 Hack: Assault Linked to China, BIG-IP Flaws Patched, Governments Challenge Alerts

Associated: Microsoft Revokes Over 200 Certificates to Disrupt Ransomware Marketing campaign

Associated: Hackers Steal Delicate Information From Public sale Home Sotheby’s

Security Week News Tags:Air, Airlines, American, Envoy, Hack, Hit, Oracle, Subsidiary

Post navigation

Previous Post: MSS Claims NSA Used 42 Cyber Tools in Multi-Stage Attack on Beijing Time Systems
Next Post: Canva Down – Suffers Global Outage, Leaving Millions of Users Inaccessible

Related Posts

UK’s Ransomware Payment Ban: Bold Strategy or Dangerous Gamble? Security Week News
Canadian Airline WestJet Hit by Cyberattack Security Week News
Proofpoint to Acquire Hornetsecurity in Reported $1 Billion Deal Security Week News
Thousands Hit by The North Face Credential Stuffing Attack Security Week News
AI Supply Chain Attack Method Demonstrated Against Google, Microsoft Products Security Week News
Ransomware Groups, Chinese APTs Exploit Recent SAP NetWeaver Flaws Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • NSO Ordered to Stop Hacking WhatsApp, but Damages Cut to $4 Million
  • Canva Down – Suffers Global Outage, Leaving Millions of Users Inaccessible
  • American Airlines Subsidiary Envoy Air Hit by Oracle Hack
  • MSS Claims NSA Used 42 Cyber Tools in Multi-Stage Attack on Beijing Time Systems
  • New DefenderWrite Tool Let Attackers Inject Malicious DLLs into AV Executable Folders

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • NSO Ordered to Stop Hacking WhatsApp, but Damages Cut to $4 Million
  • Canva Down – Suffers Global Outage, Leaving Millions of Users Inaccessible
  • American Airlines Subsidiary Envoy Air Hit by Oracle Hack
  • MSS Claims NSA Used 42 Cyber Tools in Multi-Stage Attack on Beijing Time Systems
  • New DefenderWrite Tool Let Attackers Inject Malicious DLLs into AV Executable Folders

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News