Bimbo Bakeries USA has confirmed that personal employee data was compromised after attackers exploited a previously unknown vulnerability in Oracle’s E-Business Suite (EBS). The breach, which involved a zero-day flaw, appears connected to the Clop ransomware group’s campaign targeting unpatched Oracle customers.
The Flaw and the Fallout
The incident centers on a remote code execution bug in EBS’s BI Publisher Integration component, part of the Concurrent Processing module. Rated 9.8 on the CVSS scale, this flaw (widely identified as CVE-2025-61882) allows attackers to run code on unpatched servers without credentials. That matches the behavior seen in related Clop breaches.
The breach timeline reportedly began when the company’s third-party vendor using Oracle EBS was compromised. Bimbo discovered malicious activity on December 6, 2025, when attackers accessed files stored in the EBS platform. An emergency patch from Oracle followed in early October 2025, but the company only confirmed exposure of personal data—including employee names and Social Security numbers—on August 19, 2026. At that point, state breach-notification rules were triggered.
Response, Risks, and Recommendations
Upon realizing the breach, Bimbo immediately applied Oracle’s emergency patches and initiated a full forensic review. The company is also re-examining its vendor relationships, offering affected individuals a year of free credit monitoring and fraud support through Cyberscout.
Security experts are warning that anyone still running Oracle EBS versions 12.2.3 through 12.2.14 without the October 2025 emergency patch remains vulnerable. They advise auditing past BI Publisher logs for suspicious activities dating back to mid-2025 and rotating all credentials tied to EBS integrations. With the stolen data including Social Security numbers, there’s heightened risk of identity theft or phishing attacks tied to the breach.
Based on the vendor match, attack timeline, and nature of the vulnerability, this breach aligns with other Oracle EBS attacks attributed to Clop. Major targets in recent months have included universities, media organizations, and enterprise customers exposed via the same zero-day. While Bimbo has not publicly confirmed whether ransom demands were made, the company has joined a long list of victims of this accelerating threat.
Ultimately, this incident underscores how critical it is for organizations using widely deployed business systems like Oracle EBS to stay abreast of patch releases, to enforce systematic vendor oversight, and to monitor for suspicious behavior proactively. For Bimbo’s employees, the stolen Social Security data could translate into long-term risks if misused.
Analytical angle: This breach represents more than just another security failure—it illustrates a growing pattern in which threat actors exploit critical vulnerabilities long before fixes are widely applied. Oracle EBS powers mission-critical operations across industries, meaning delayed patching or opaque vendor chains can dramatically increase risk. Companies should consider not only reactive measures like patching and monitoring, but also proactive governance such as contractual security requirements for vendors, continuous patch compliance, and investment in resilient architectures. Only then can they avoid becoming the next Clop victim.