Allianz UK joins growing list of Clop’s Oracle E-Business Suite victims
(2025/11/10)
- Reference: 1762768093
- News link: https://www.theregister.co.uk/2025/11/10/allianz_uk_joins_growing_list/
- Source link:
Allianz UK confirms it was one of the many companies that fell victim to the Clop gang's Oracle E-Business Suite (EBS) attack after crims reported that they had attacked a subsidiary.
The criminal crew behind the wave of zero-day data raids claimed to have attacked Allianz-owned British insurer Liverpool Victoria (LV) on Tuesday, but a spokesperson for its parent company waved away these allegations.
Allianz UK told The Register that the attack compromised the data of its customers only, and there was no impact on LV's customers or systems at all.
[1]
It confirmed 80 current Allianz UK customers and 670 previous customers were affected, all of whom had been contacted and offered support.
[2]
[3]
The attackers broke in via the company's Oracle EBS, which is used in its personal lines business, covering products such as home, car, pet, travel, and other types of personal insurance.
Allianz UK refused to comment on whether it was extorted by the criminals working for Clop, but said that it reported itself to the Information Commissioner's Office, although the watchdog did not respond to our efforts to verify this claim.
[4]
The insurance giant also confirmed that the attack was entirely separate from an earlier breach at Allianz Life, one of its US subsidiaries, the [5]majority of whose 1.4 million customers had their data compromised in July.
It joins a long list of organizations to have been hit by Clop using the same EBS exploit, among which was the [6]Washington Post , which confirmed a related attack on Thursday.
American Airlines' subsidiary, [7]Envoy Air , also confirmed it was among the bigger victims of Clop's EBS raids last month.
[8]
Researchers at Google offered their view on the situation in early October, positing that "dozens" of organizations were likely affected, and that attacks exploiting CVE-2025-61882 (9.8) could have begun as early as July, three months before any detections were made public.
[9]Majority of 1.4M customers caught in Allianz Life data heist
[10]3.7M breach notification letters set to flood North America's mailboxes
[11]Clop-linked crims shake down Oracle execs with data theft claims
[12]Gootloader malware back for the attack, serves up ransomware
"We're still assessing the scope of this incident, but we believe it affected dozens of organizations," John Hultquist, chief analyst at Google Threat Intelligence Group, [13]told The Register at the time.
"Some historic Clop data extortion campaigns have had hundreds of victims. Unfortunately, large-scale zero-day campaigns like this are becoming a regular feature of cybercrime."
Clop made a name for itself off the back of the supply chain [14]attack on Progress' MOVEit MFT software – another zero-day attack in 2023 that has affected more than 95 million individuals and nearly 3,000 organizations to date. ®
Get our [15]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aRHFyFPaq_zTlTfekcxwYAAAAAA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aRHFyFPaq_zTlTfekcxwYAAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aRHFyFPaq_zTlTfekcxwYAAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aRHFyFPaq_zTlTfekcxwYAAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2025/07/28/allianz_life_data_breach/
[6] https://www.reuters.com/sustainability/boards-policy-regulation/google-says-dozens-organizations-affected-by-oracle-linked-hacking-campaign-2025-10-09/
[7] https://www.theregister.com/2025/10/17/american_airlines_envoy_oracle_ebs/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aRHFyFPaq_zTlTfekcxwYAAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2025/07/28/allianz_life_data_breach/
[10] https://www.theregister.com/2025/10/01/north_american_data_breaches/
[11] https://www.theregister.com/2025/10/02/clop_oracle_extortion/
[12] https://www.theregister.com/2025/11/06/gootloader_back_ransomware/
[13] https://www.theregister.com/2025/10/09/miscreants_head_start_oracle_ebs_invasion/
[14] https://www.theregister.com/2023/06/15/clop_broke_into_the_doe/
[15] https://whitepapers.theregister.com/
The criminal crew behind the wave of zero-day data raids claimed to have attacked Allianz-owned British insurer Liverpool Victoria (LV) on Tuesday, but a spokesperson for its parent company waved away these allegations.
Allianz UK told The Register that the attack compromised the data of its customers only, and there was no impact on LV's customers or systems at all.
[1]
It confirmed 80 current Allianz UK customers and 670 previous customers were affected, all of whom had been contacted and offered support.
[2]
[3]
The attackers broke in via the company's Oracle EBS, which is used in its personal lines business, covering products such as home, car, pet, travel, and other types of personal insurance.
Allianz UK refused to comment on whether it was extorted by the criminals working for Clop, but said that it reported itself to the Information Commissioner's Office, although the watchdog did not respond to our efforts to verify this claim.
[4]
The insurance giant also confirmed that the attack was entirely separate from an earlier breach at Allianz Life, one of its US subsidiaries, the [5]majority of whose 1.4 million customers had their data compromised in July.
It joins a long list of organizations to have been hit by Clop using the same EBS exploit, among which was the [6]Washington Post , which confirmed a related attack on Thursday.
American Airlines' subsidiary, [7]Envoy Air , also confirmed it was among the bigger victims of Clop's EBS raids last month.
[8]
Researchers at Google offered their view on the situation in early October, positing that "dozens" of organizations were likely affected, and that attacks exploiting CVE-2025-61882 (9.8) could have begun as early as July, three months before any detections were made public.
[9]Majority of 1.4M customers caught in Allianz Life data heist
[10]3.7M breach notification letters set to flood North America's mailboxes
[11]Clop-linked crims shake down Oracle execs with data theft claims
[12]Gootloader malware back for the attack, serves up ransomware
"We're still assessing the scope of this incident, but we believe it affected dozens of organizations," John Hultquist, chief analyst at Google Threat Intelligence Group, [13]told The Register at the time.
"Some historic Clop data extortion campaigns have had hundreds of victims. Unfortunately, large-scale zero-day campaigns like this are becoming a regular feature of cybercrime."
Clop made a name for itself off the back of the supply chain [14]attack on Progress' MOVEit MFT software – another zero-day attack in 2023 that has affected more than 95 million individuals and nearly 3,000 organizations to date. ®
Get our [15]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aRHFyFPaq_zTlTfekcxwYAAAAAA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aRHFyFPaq_zTlTfekcxwYAAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aRHFyFPaq_zTlTfekcxwYAAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aRHFyFPaq_zTlTfekcxwYAAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2025/07/28/allianz_life_data_breach/
[6] https://www.reuters.com/sustainability/boards-policy-regulation/google-says-dozens-organizations-affected-by-oracle-linked-hacking-campaign-2025-10-09/
[7] https://www.theregister.com/2025/10/17/american_airlines_envoy_oracle_ebs/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aRHFyFPaq_zTlTfekcxwYAAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2025/07/28/allianz_life_data_breach/
[10] https://www.theregister.com/2025/10/01/north_american_data_breaches/
[11] https://www.theregister.com/2025/10/02/clop_oracle_extortion/
[12] https://www.theregister.com/2025/11/06/gootloader_back_ransomware/
[13] https://www.theregister.com/2025/10/09/miscreants_head_start_oracle_ebs_invasion/
[14] https://www.theregister.com/2023/06/15/clop_broke_into_the_doe/
[15] https://whitepapers.theregister.com/
I love my data, today and tomorrow.
Judge Mental
" the attack compromised the data of its customers only, and there was no impact on LV's customers or systems at all."
https://www.lv.com Why are you in business if not to protect your customers ?
The customers data is theirs to protect, you cannot steal data without compromising systems.
Signed,
Ex LV and Allianz customer
New business model?
AMBxx
Oracle's customers have always been considered hostages to Oracles licensing.
Maybe this is just Oracle taking a more direct route to their customers' money?
"Unfortunately, large-scale zero-day campaigns like this"
are becoming a lot easier since companies are stupid enough to rely of The Cloud TM 's single point of failure.
Education is hard. For companies, it'll be measured in billions.
For CEOs, it's be measured in bonuses lost.
Now you can wonder why this stupidity continues . . .