INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Oracle EBS 2025 campaign leaks sensitive data at Madison Square
| 2026-03-03 15:42 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
On March 3, 2026, Madison Square Garden was affected by a data breach linked to the 2025 Oracle E-Business Suite hacking campaign. The Cl0p ransomware group exploited zero-day flaws in Oracle's application to access sensitive information from over 100 organizations, including MSG. The incident involved leaked more than 210GB of archived files containing business records related to hiring or payments made to individuals, exposing personal data such as names and Social Security numbers. The attack works by exploiting a critical vulnerability tracked as CVE-2025-61882 (CVSS 9.8) in the Oracle E-Business Suite, allowing unauthenticated remote attackers to take control of the system. As of now, Madison Square Garden has notified affected individuals and offered complimentary credit monitoring services through Cyberscout to help detect misuse of personal information.
Technical Mitigations AI-generated
• Apply the Oracle EBS 2025 patch (CVE-2025-61882) to prevent exploitation of the critical vulnerability.
• Monitor for suspicious activity related to the Cl0p ransomware group, such as unusual login attempts or data access patterns.
• Use a reputable credit monitoring service like Cyberscout to detect potential misuse of personal information.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-61882CVE-2025-61882
Target & Sectors
Global Scope
Incident Timeline
November 2025
Threat actors leaked more than 210GB of Madison Square Garden's archived files, exposing sensitive information.
Click on any entity below to view its context and source!
data_breach
210 GB
MSG refused to pay the ransom, then the extortion group leaked more than 210GB of the company’s archived files, exposing sensitive information.
December 2025
Threat actors exploited the CVE-2025-61882 vulnerability in Oracle EBS 2025 to target Madison Square Garden, resulting in a leak of sensitive data.
Click on any entity below to view its context and source!
infrastructure
9.8
In October 2025,
Oracle released an emergency patch to address a critical vulnerability, tracked as
CVE-2025-61882
(CVSS 9.8) in its E-Business Suite.
2026/03/03
The 2025 Oracle EBS hacking campaign, led by the Cl0p ransomware group, exploited zero-day flaws to access sensitive data from over 100 organizations, including Madison Square Garden.
Click on any entity below to view its context and source!
victims
100 organizations
In the Oracle EBS hacking campaign, the
Cl0p ransomware
group exploited zero-day flaws to access data from over 100 organizations, including MSG, in November 2025.
Tactical Metrics
Metrics
victims
100
Organizations
Click for context!
In the Oracle EBS hacking campaign, the
Cl0p ransomware
group exploited zero-day flaws to access data from over 100 organizations, including MSG, in November 2025.
Metrics
data_breach
210
Gb
MSG refused to pay the ransom, then the extortion group leaked more than 210GB of the company’s archived files, exposing sensitive information.
Metrics
infrastructure
9.8
Software Version
In October 2025,
Oracle released an emergency patch to address a critical vulnerability, tracked as
CVE-2025-61882
(CVSS 9.8) in its E-Business Suite.
Intelligence Sources
Security Affairs
2026-03-03
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:53
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
MSG
entity
6x
timeline
Temporal Reference
2025
date
3x
tactic
Cyber Operation Type
Data Breach
tactic
Contextual Telemetry
Context Block
8 METRICS
source region
Origin Country
United States
country
victims
Organizations
100
organizations
data breach
Gb
210
gb
vulnerability
Exploited CVE
CVE-2025-61882
cve
vulnerability
CVSS Score
10
score
infrastructure
Software Version
9.8
version
general metric
Ebs
2,025
ebs
general metric
Companies
100
companies
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.