Published September 12, 2026 — Redwood City, California. An Oracle E-Business Suite (EBS) attack campaign has compromised multiple Fortune-1000 enterprises in 2026. The most publicly disclosed victim is Michelin (300GB exfiltrated, disclosed September 11, 2026). Oracle EBS handles HR, finance, and supply chain operations for thousands of organizations worldwide, making successful exploitation high-impact.
Data last verified September 12, 2026 from TechJack Solutions SCC Intel coverage of the Oracle EBS attack campaign, BleepingComputer reporting, and Oracle Critical Patch Update advisories.
Quick Answer
An Oracle E-Business Suite (EBS) attack campaign has compromised multiple Fortune-1000 enterprises in 2026. The most publicly disclosed victim is Michelin (~300GB exfiltrated, September 11, 2026). Oracle EBS handles mission-critical HR, finance, and supply chain operations. The campaign exploits unpatched Oracle CPU vulnerabilities, stolen admin credentials, and internet-exposed EBS instances. Organizations running Oracle EBS should treat this as an active threat: inventory instances, validate patch levels, audit admin logs, and implement network segmentation (TechJack Solutions, September 11, 2026; BleepingComputer, 2026; Oracle CPU advisories, 2025-2026).
The Oracle EBS attack campaign: timeline
The campaign has been active throughout 2026. Key events:
| Date | Event |
|---|---|
| Q1 2026 | Initial reconnaissance and exploitation of vulnerable EBS instances |
| Q2 2026 | Campaign expands to multiple Fortune-1000 enterprises |
| April-July 2026 | Persistent access established at multiple victims; data staging |
| August 2026 | Data exfiltration phase; multiple victims experience large-scale data theft |
| September 11, 2026 | Michelin publicly discloses breach (300GB) |
| September 12, 2026 | Security researchers confirm broader campaign pattern |
| Ongoing | Investigation, attribution, remediation across multiple victims |
Source: TechJack Solutions SCC Intel (September 2026); BleepingComputer coverage (2026).
Victim profile and targeting
The Oracle EBS attack campaign targets Fortune-1000 enterprises with substantial Oracle EBS footprints. Victim characteristics:
- Industry: Manufacturing (Michelin), retail, healthcare, financial services, government.
- Size: $5B+ revenue (Fortune-1000).
- Geography: Global; primary concentration in North America and Europe.
- EBS deployment: Large, complex deployments with 100+ EBS modules; 1,000+ named users.
- IT maturity: Mature security programs, yet still vulnerable due to EBS complexity.
The campaign's focus on large enterprises reflects:
- High data value: large enterprises hold concentrated HR, financial, and supply chain data.
- Higher ransom tolerance: larger organizations may pay higher ransoms to restore operations.
- Supply-chain impact: attacks on large manufacturers like Michelin affect global supply chains.
Attack chain analysis
Based on the pattern observed across victims, the Oracle EBS campaign uses a multi-stage attack chain:
Stage 1: Reconnaissance
Attackers identify Oracle EBS instances using:
- Shodan and Censys scans for internet-exposed Oracle EBS Web tier.
- DNS enumeration for EBS subdomains (e.g., ebs.example.com, oracle.example.com).
- OSINT for Oracle consulting firms with privileged EBS access.
- LinkedIn reconnaissance for Oracle EBS administrators and DBAs.
Stage 2: Initial access
Multiple vectors observed:
- Unpatched Oracle CPU vulnerabilities: many organizations fall 3-6 months behind on Oracle CPUs; specific EBS module vulnerabilities are exploitable.
- Stolen admin credentials: obtained via phishing, credential dumps on dark web markets, or compromised third-party consultants.
- Internet-exposed EBS instances: particularly Oracle E-Business Suite Mobile and third-party integration platforms running on the same WebLogic server as EBS.
- WebLogic/Forms vulnerabilities: the application server tier (Oracle WebLogic Server) and Forms tier are common attack surfaces.
Stage 3: Privilege escalation
After initial access, attackers escalate to:
- EBS sysadmin: full administrative access to EBS modules (HR, finance, supply chain).
- Database admin: SYSTEM or DBA access to the underlying Oracle database.
- Operating system root: on the EBS application server, granting full control.
Stage 4: Lateral movement
From EBS, attackers pivot to:
- Connected databases (HR data warehouse, financial reporting database, supply chain analytics).
- Identity systems (Oracle Internet Directory, Active Directory integrated via LDAP).
- File shares and document management systems containing EBS-related documents.
- Backup systems and disaster recovery sites.
Stage 5: Data staging and exfiltration
Attackers identify and stage high-value data:
- HR data: employee PII, payroll, compensation, benefits, performance reviews.
- Financial data: general ledger, AP/AR, financial statements, customer credit data.
- Supply chain data: vendor lists, contract terms, pricing, volume commitments.
- Customer data: B2B customer orders, contacts, and account information.
Data is staged in compressed archives on EBS servers, then exfiltrated over weeks or months using HTTPS or DNS tunneling to avoid detection (Oracle CPU advisories; TechJack Solutions, 2026).
Stage 6: Optional ransomware or extortion
Some incidents include encryption of EBS data and ransom demands. The pattern matches Cl0p, BlackCat, and Akira ransomware operations, though no public attribution has been made.
Why Oracle EBS is structurally vulnerable
Several factors make Oracle EBS disproportionately vulnerable:
| Vulnerability factor | Description |
|---|---|
| Mission-critical data concentration | HR, finance, supply chain in single instance |
| Complexity | 200+ components across multiple tiers |
| Patch lag | Quarterly CPU cadence; 3-6 month average patch lag |
| Internet exposure | EBS Mobile, integration platforms, third-party access |
| Default configurations | Some modules ship with default credentials or excessive permissions |
| Long lifecycle | 15-20 year deployment windows accumulate vulnerabilities |
| Privileged access management | DBA and EBS sysadmin accounts often shared or poorly controlled |
These factors make Oracle EBS the highest-value, highest-risk ERP platform (Oracle, 2026).
Defensive playbook for Oracle EBS environments
- Inventory all EBS instances: production, development, test, DR. Include all tiers: WebLogic, Forms, Concurrent Processing, database.
- Validate patch level: check against Oracle CPU advisories from October 2025, January 2026, April 2026, July 2026, and (when released) October 2026.
- Audit admin access logs: from August 2026 forward for unexpected activity, after-hours logins, or unfamiliar IPs.
- Rotate credentials: EBS sysadmin, database sys/system, integration credentials, third-party consultant accounts.
- Enable Oracle Database Vault: enforce separation of duties, prevent direct database access bypassing EBS.
- Enable Oracle Advanced Security (TDE): encrypt data at rest in the EBS database.
- Implement network segmentation: isolate EBS Web tier from the public internet. Use VPN or zero-trust gateway for remote access.
- Restrict outbound network: EBS servers should not have unrestricted internet access; implement egress filtering.
- Deploy DLP: data loss prevention tools to detect large data transfers from EBS servers.
- Enable audit vault: forward EBS audit logs to a centralized SIEM with real-time alerting on admin actions.
- Implement PAM: privileged access management for EBS admin accounts - session recording, just-in-time access, password rotation.
- Review third-party access: audit Oracle consulting firm access; restrict to specific tasks with session limits.
Migration to Oracle Fusion Cloud as a long-term strategy
For organizations with long-term security concerns about Oracle EBS, migration to Oracle Fusion Cloud Applications provides several benefits:
- Cloud-managed patching: Oracle handles CPU patching in Fusion Cloud; no on-premises patch lag.
- Cloud security controls: Oracle Cloud Infrastructure provides network isolation, encryption at rest, identity management.
- Modern architecture: Fusion uses a more modern architecture with better separation of duties.
- Continuous monitoring: Oracle's cloud monitoring detects anomalous behavior in real-time.
However, migration is complex and expensive. Organizations should weigh:
- Cost: Fusion Cloud licensing and migration costs can be significant.
- Time: typical migration takes 18-36 months.
- Risk: migration carries its own risks - data integrity, integration breakage, user adoption.
- Data sovereignty: cloud may not be appropriate for all organizations or data.
For most organizations, prompt patching and hardening of existing Oracle EBS is the immediate response; long-term migration to Fusion Cloud should be planned but not rushed (Oracle, 2026).
FAQ
How does this attack campaign compare to the SolarWinds supply-chain attack?
Both attacks target enterprise software widely deployed across Fortune-1000. SolarWinds (2019-2020) compromised a single vendor (SolarWinds Orion) to access ~18,000 organizations including DHS, State, Treasury. The Oracle EBS campaign exploits multiple vectors (unpatched vulnerabilities, stolen credentials, supply-chain) against organizations running EBS. SolarWinds was a nation-state attack (Russian SVR); the EBS campaign appears to be financially motivated but may have nation-state involvement (TechJack Solutions; CISA, 2020-2026).
Is Oracle releasing an emergency patch for the EBS vulnerabilities exploited in the campaign?
Oracle's quarterly Critical Patch Update (CPU) cadence is January, April, July, October. The next CPU is October 2026. Oracle may release out-of-band emergency patches for specific vulnerabilities if active exploitation is confirmed and severity warrants. For non-emergency vulnerabilities, the October 2026 CPU is the next opportunity for fixes. Organizations should apply interim compensating controls (Oracle CPU advisories, 2026).
Should I consider switching from Oracle EBS to SAP or Workday?
Platform switching is a multi-year strategic decision driven by business needs (acquisitions, market changes, competitive positioning). Security concerns alone rarely justify a platform switch. For most organizations, the right response is: immediate patching and hardening of EBS, planned migration to Oracle Fusion Cloud (lower-effort than SAP/Workday), and continued investment in EBS security controls. A complete platform switch should be evaluated on total cost of ownership and business fit, not solely on security (Oracle; SAP; Workday, 2026).
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read more
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.








