← Michelin

2026 Michelin — ~300GB+ internal data claimed (Oracle EBS; CL0p extortion)

2026 Unknown records affected Share on X

Data compromised

300GB+ corporate files and internal archives per leak-site claims; Michelin minimized sensitivity of content

Technical writeup

Michelin Group confirmed a data incident on March 11, 2026 linked to exploitation of Oracle E-Business Suite (EBS) in a broader CL0p/FIN11-style extortion wave affecting 100+ organizations in industry reporting. Threat actors claimed roughly 300–315 GB of internal archives; Michelin described a localized exposure and stated compromised files did not include sensitive technical IT secrets, with no encryption of operational systems in public descriptions (data-extortion pattern). Independent reporting tied the campaign to zero-day or high-severity Oracle EBS issues (e.g., CVE-2025-61882 cited in security analyses). Exact count of affected individuals is not public—impact is framed as large-scale corporate data exposure rather than a consumer headcount.

Root cause

Exploitation of Oracle E‑Business Suite vulnerabilities; CL0p-style extortion / data theft (multi-target campaign)

References