2025 Emerson — alleged Oracle E-Business Suite zero-day wave; Cl0p leak-site postings (Oct; industrial vendor context)
Data compromised
Enterprise finance/procurement and adjacent engineering business records implied by EBS context—specific validated categories pending vendor transparency
Technical writeup
In October 2025, SecurityWeek, SC Media, and peer outlets reported Emerson alongside Schneider Electric as high-profile industrial victims of a concerted Oracle E-Business Suite (EBS) exploitation spree publicly linked to FIN11 / Cl0p-adjacent data-extortion operators, with leak-site marketing citing very large compressed exfiltration volumes. As with most criminal-site disclosures, corporate forensic confirmation of full file trees and precise PII population was not uniformly contemporaneous in open press; treat terabyte claims as actor positioning unless Emerson releases detailed metrics.
Root cause
External exploitation of enterprise Oracle EBS attack surface attributed in trade press to zero-day/chained flaw abuse with subsequent extortion posts