← Bimbo Bakeries USA

2026 Bimbo Bakeries USA — Oracle E-Business Suite zero-day; SSNs in files (CA AG)

2026 Unknown records affected Share on X

Data compromised

Name and Social Security number (per California sample notice)

Technical writeup

Verified California AG notice dated August 31, 2026. Bimbo Bakeries USA said a zero-day in Oracle’s E-Business Suite allowed unauthorized acquisition of files; patches applied; investigation determined unauthorized acquisition by December 6, 2025, and on August 19, 2026 identified a file containing the recipient’s name and SSN. 12 months credit monitoring offered. National count not published in sample letter; recordsAffected 0; companyConfirmed true. Related to the broader 2025 Oracle EBS extortion campaign affecting multiple customers.

Root cause

Zero-day vulnerability in Oracle E-Business Suite allowed unauthorized parties to acquire application files; investigation determination December 6, 2025; affected file identified August 19, 2026

References