Bimbo Bakeries confirms data stolen in Oracle EBS zero-day attack
Brief
Bimbo Bakeries USA, the American arm of the world’s largest baking company, has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS), joining a growing list of organizations swept up in the Clop ransomware gang’s global extortion campaign against Oracle customers.
In a notification letter dated August 31, 2026, and filed with the California Attorney General’s office on September 4, as detailed in the official filing published by the California Attorney General’s Office , the bakery giant said the incident traced back to a third-party vendor that relied on Oracle EBS.
Bimbo Oracle EBS Data Breach
The company disclosed that its investigation determined on December 6, 2025, that attackers had exploited the zero-day to acquire files stored within the platform.
All credited sources
Highest-trust first. Dates are the publisher's original publish time.
Bimbo Bakeries confirms data stolen in Oracle EBS zero-day attack
Bimbo Bakeries USA has disclosed a data breach caused by the exploitation of an Oracle E-Business Suite (EBS) zero-day that allowed attackers to steal files containing names and Social Security numbers. The company says it determined on December 6, 2025, that unauthorized parties had acquired files stored in its Oracle EBS environment. However, it was …
The post Bimbo Bakeries confirms data stolen in Oracle EBS zero-day attack appeared first on CyberInsider .
Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack
Bimbo Bakeries USA, the American arm of the world’s largest baking company, has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS), joining a growing list of organizations swept up in the Clop ransomware gang’s global extortion campaign against Oracle customers.
In a notification letter dated August 31, 2026, and filed with the California Attorney General’s office on September 4, as detailed in the official filing published by the California Attorney General’s Office , the bakery giant said the incident traced back to a third-party vendor that relied on Oracle EBS.
Bimbo Oracle EBS Data Breach
The company disclosed that its investigation determined on December 6, 2025, that attackers had exploited the zero-day to acquire files stored within the platform.
Bimbo Bakeries said it applied Oracle’s emergency patches as soon as it learned of the flaw and launched a forensic review to determine exactly what data had been exposed.
That review took months to complete. It wasn’t until August 19, 2026, that the company confirmed one of the stolen files contained victims’ names and Social Security numbers, triggering the formal notification process required under state breach-disclosure laws.
While Bimbo Bakeries’ letter doesn’t name the specific flaw, the timeline and vendor match a widely documented campaign tied to CVE-2025-61882, a critical unauthenticated remote code execution vulnerability in the BI Publisher Integration component of Oracle EBS’s Concurrent Processing module.
Rated 9. 8 on the CVSS scale, the bug let attackers run arbitrary code on unpatched EBS servers without needing valid credentials. Google-owned Mandiant traced exploitation back to August 2025, weeks before Oracle issued an emergency patch on October 4, 2025.
