TechNewsReel
Live

Bimbo Bakeries USA Data Breach Exposes Employee SSNs via Oracle Zero-Day

A critical vulnerability in a third-party vendor's Oracle E-Business Suite led to the theft of sensitive employee data.

TechNewsReel Newsroom · September 8, 2026

Bimbo Bakeries USA (BBU) has confirmed a significant data breach that exposed the names and Social Security numbers of its employees. The incident underscores the persistent danger of supply-chain vulnerabilities in large-scale corporate environments.

The breach originated from a zero-day vulnerability within a third-party vendor's Oracle E-Business Suite (EBS) platform. BBU first discovered the exploitation on December 6, 2025. However, it took until August 19, 2026, for the company to confirm that Social Security numbers had been exposed. BBU officially reported the incident to the California Attorney General's Office on September 4, 2026.

The Technical Failure

The attack leveraged CVE-2025-61882, a critical remote code execution flaw located in the BI Publisher Integration component of the Oracle EBS. This specific vulnerability carried a CVSS score of 9.8, indicating a severe risk level. While Oracle released emergency patches to address the flaw on October 4, 2025, and the Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog, the vulnerability was successfully exploited in this instance via a third-party provider.

A Global Extortion Campaign

This breach is not an isolated event but part of a wider global extortion campaign targeting Oracle EBS customers. Security researchers have attributed these attacks to the Clop ransomware gang. The campaign has been aggressive and high-profile, with other reported targets including The Washington Post and Harvard University. By targeting the enterprise software that manages core business operations, the attackers were able to gain access to highly sensitive data across diverse industries.

Industry Implications

This incident highlights the severe risks associated with the modern software supply chain. When a major corporation relies on third-party vendors for enterprise resource planning, a single flaw in a vendor's environment can bypass the primary company's internal security perimeters. Furthermore, the timeline of this breach reveals a troubling gap in forensic visibility; the eight-month delay between the initial discovery of the exploit in December 2025 and the confirmation of SSN theft in August 2026 demonstrates how difficult it can be to determine the full scope of data exfiltration in complex enterprise systems.

What's Next

As BBU manages the aftermath of the exposure, the industry will be watching for further disclosures regarding the third-party vendor involved. The incident serves as a reminder for organizations to not only patch their own systems but to demand rigorous vulnerability management and transparency from their software partners. It remains to be seen if other Oracle EBS users, who may have delayed the October 2025 patches, will report similar intrusions.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.