2025 Worley — Cl0p leak-site listing amid Oracle E‑Business Suite exploitation wave
Data compromised
Unconfirmed exfiltration volumes—leak site used as pressure tactic
Technical writeup
Insurance Business and CyberDaily reported that Cl0p added Sydney-headquartered Worley to its extortion portal in late November 2025 as part of a broader Oracle E-Business Suite zero-day campaign affecting dozens of industrials. Worley publicly activated IR retainers with Oracle and outside forensics while stating it had not yet validated data impact—a common pattern when criminals choreograph leak listings ahead of forensic conclusions.
Root cause
Claimed exploitation of Oracle enterprise suite vulnerabilities leveraged by Cl0p for mass extortion (per trade-press reconstruction)
References
- https://www.insurancebusinessmag.com/au/news/cyber/sydney-engineering-firm-targeted-in-cyber-extortion-campaign-557918.aspx
- https://www.cyberdaily.au/security/12940-exclusive-sydney-headquartered-engineering-firm-worley-listed-by-cl0p-extortion-gang
- https://www.redpacketsecurity.com/clop-ransomware-victim-worley-com/