Published September 12, 2026 — Lansing, Michigan. Michelin confirmed on September 11, 2026 that the company suffered a data breach tied to an active Oracle E-Business Suite (EBS) attack campaign. Approximately 300GB of data was exfiltrated. Oracle EBS is an enterprise resource planning platform handling HR, finance, and supply chain operations - making successful exploitation high-impact for any affected organization.
Data last verified September 12, 2026 from TechJack Solutions SCC Intel coverage of the Michelin breach (September 11, 2026), BleepingComputer reporting, and Oracle Critical Patch Update advisories.
Quick Answer
Michelin confirms a data breach tied to an Oracle E-Business Suite (EBS) attack campaign, disclosed on September 11, 2026. Approximately 300GB of data was exfiltrated. Oracle EBS handles HR, finance, and supply chain data for Fortune 1000 enterprises - making successful exploitation high-impact. Organizations running Oracle EBS should treat this as an active threat requiring immediate inventory of EBS instances, validation of patch levels, and audit of access logs (TechJack Solutions, September 11, 2026; BleepingComputer, September 11, 2026; Oracle Critical Patch Update advisories, 2025-2026).
What we know about the Michelin breach
| Detail | Information |
|---|---|
| Victim | Michelin (French tire manufacturer, Fortune Global 500) |
| Disclosed | September 11, 2026 |
| Data exfiltrated | ~300GB |
| Vector | Oracle E-Business Suite (EBS) exploitation |
| Threat actor | Not yet publicly attributed |
| Data types | Not fully disclosed; presumed to include HR, finance, supply chain |
| Reporting sources | TechJack Solutions SCC Intel, BleepingComputer |
Source: TechJack Solutions SCC Intel (September 11, 2026); BleepingComputer (September 11, 2026).
The Oracle EBS attack campaign: a broader pattern
The Michelin breach is not an isolated incident. It is part of a broader attack campaign targeting Oracle EBS deployments across multiple Fortune 1000 enterprises throughout 2026. The campaign pattern observed by security researchers:
- Reconnaissance - attackers identify internet-exposed Oracle EBS instances using tools like Shodan and Censys.
- Initial access - exploitation of unpatched EBS vulnerabilities, stolen admin credentials, or supply-chain compromise of third-party Oracle consultants.
- Privilege escalation - using EBS module-level permissions to gain database admin access.
- Lateral movement - moving from EBS to connected systems (database servers, identity systems, file shares).
- Data exfiltration - bulk export of HR, finance, and supply chain data over weeks or months.
- Optional ransomware deployment - some incidents include encryption of EBS data and ransom demands.
The campaign's success rate is high because Oracle EBS environments are notoriously difficult to patch — a typical EBS installation has hundreds of components with quarterly Critical Patch Updates (CPUs), and many organizations fall behind by 6-18 months. Attackers have specifically targeted known-but-unpatched vulnerabilities in the Oracle CPU advisories (Oracle, 2025-2026; TechJack Solutions, September 11, 2026).
Why Oracle EBS is uniquely vulnerable
Oracle E-Business Suite has structural vulnerabilities that make it a frequent attack target:
- Mission-critical data concentration - a single EBS instance contains all HR records (employee PII, payroll, benefits), all financial records (general ledger, AP/AR, financial statements), and all supply chain data (vendors, purchase orders, inventory). One compromise exposes all of it.
- Complexity - a typical EBS installation has 200+ components across multiple application tiers, making security assessment difficult.
- Patch lag - Oracle releases Critical Patch Updates quarterly (January, April, July, October). Many organizations apply CPUs 3-6 months late, or skip them entirely in development/test environments.
- Default credentials - some EBS modules ship with default admin credentials that are not always changed during deployment.
- Internet exposure - EBS instances are often exposed to the internet via Oracle E-Business Suite Mobile or third-party integration platforms.
- Long lifecycle - EBS releases stay in production for 15-20 years, accumulating vulnerabilities over time.
Oracle has shifted strategic focus to Oracle Fusion Cloud Applications, but thousands of organizations still run EBS for mission-critical workloads (Oracle, 2026).
Immediate actions for organizations running Oracle EBS
- Inventory all Oracle EBS instances across production, development, test, and DR environments. Include all application tiers (WebLogic, Forms, Concurrent Processing) and database tiers.
- Validate patch level - check each instance against Oracle's October 2025, January 2026, April 2026, July 2026, and October 2026 (pending) Critical Patch Updates. Apply missing CPUs within 7 days for high-severity EBS fixes.
- Audit access logs from August 2026 forward for unexpected admin activity, especially logins from unfamiliar IPs or after-hours patterns.
- Rotate credentials - EBS sysadmin passwords, database sys/system passwords, integration credentials, third-party consultant credentials.
- Review outbound network traffic from EBS servers for large data transfers to unfamiliar destinations. Oracle EBS should not typically transfer 300GB+ of data in short periods.
- Enable Oracle Database Vault to enforce separation of duties and prevent direct database access bypassing EBS application controls.
- Enable Oracle Advanced Security (Transparent Data Encryption) for EBS database files.
- Segment EBS from the internet - move EBS Web tiers behind a VPN or zero-trust gateway. Mobile access should go through Oracle Access Manager.
- Monitor for IOCs - subscribe to Oracle's security alerts and security researcher feeds for indicators of compromise.
What makes the Michelin breach different
The Michelin breach is notable for the volume of data exfiltrated (300GB) and the target (a major global manufacturer). Three factors make this attack distinctive:
- Scale - 300GB is among the largest single-vendor Oracle EBS breaches publicly disclosed. Most EBS incidents involve 5-50GB of data.
- Patient exfiltration - the volume suggests the attackers had weeks or months of access before detection, not a smash-and-grab.
- Industry implications - the manufacturing sector's heavy reliance on Oracle EBS for supply chain operations makes this attack pattern a sector-wide threat.
Michelin's response will likely follow GDPR breach notification requirements (Michelin is headquartered in France), with French data-protection authority CNIL receiving notification within 72 hours of breach discovery (TechJack Solutions, September 11, 2026).
Defensive controls for Oracle EBS
| Layer | Control | Implementation |
|---|---|---|
| Network | EBS Web tier behind VPN/zero-trust | Remove EBS from public internet |
| Authentication | MFA on all EBS admin access | Oracle Access Manager + OIDC |
| Authorization | Role-based access control (RBAC) | Limit EBS duty roles to least privilege |
| Patching | Quarterly CPU within 30 days | Critical Patch Update advisory subscription |
| Database | Oracle Database Vault | Prevent direct DB access bypassing EBS |
| Encryption | Oracle Advanced Security (TDE) | Encrypt data at rest |
| Monitoring | Oracle Audit Vault + SIEM integration | Real-time admin action alerting |
| Backup | Immutable backups offline | Protect against ransomware + deletion |
Source: Oracle Security Guide for E-Business Suite (2026).
FAQ
Is the Michelin breach connected to other recent Oracle EBS attacks?
The Michelin breach is part of a broader attack campaign that has been ongoing through 2026. Multiple Fortune 1000 enterprises running Oracle EBS have been targeted. The campaign is not tied to a single threat actor group publicly; attribution is pending (TechJack Solutions, September 11, 2026).
What is the difference between Oracle EBS and Oracle Fusion Cloud Applications?
Oracle E-Business Suite (EBS) is Oracle's legacy on-premises ERP platform, originally released in 2001. Oracle Fusion Cloud Applications (Fusion) is the modern cloud-based successor, released in 2011 and now Oracle's strategic focus. Fusion runs in Oracle Cloud Infrastructure (OCI) or third-party clouds, while EBS runs on-premises on Oracle databases. Both share data models and integration patterns, but Fusion has more modern security controls. Organizations should plan EBS-to-Fusion migration as a long-term security improvement (Oracle, 2026).
Will Oracle release a security advisory for the EBS vulnerability exploited in the Michelin breach?
Oracle's quarterly Critical Patch Update advisories are released in January, April, July, and October. The October 2026 CPU (expected mid-October) is likely to include fixes for the vulnerabilities exploited in the Michelin campaign. Until then, organizations should apply all critical and high-severity EBS fixes from prior CPUs and consider additional compensating controls (Oracle Critical Patch Update schedule, 2026).
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read more
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









