Article Details

Scrape Timestamp (UTC): 2025-11-10 09:52:36.754

Source: https://www.theregister.com/2025/11/10/allianz_uk_joins_growing_list/

Original Article Text

Click to Toggle View

Allianz UK joins growing list of Clop’s Oracle E-Business Suite victims. Insurance giant’s UK arm says cybercriminals misattributed the real victim. Allianz UK confirms it was one of the many companies that fell victim to the Clop gang's Oracle E-Business Suite (EBS) attack after crims reported that they had attacked a subsidiary. The criminal crew behind the wave of zero-day data raids claimed to have attacked Allianz-owned British insurer Liverpool Victoria (LV) on Tuesday, but a spokesperson for its parent company waved away these allegations. Allianz UK told The Register that the attack compromised the data of its customers only, and there was no impact on LV's customers or systems at all. It confirmed 80 current Allianz UK customers and 670 previous customers were affected, all of whom had been contacted and offered support. The attackers broke in via the company's Oracle EBS, which is used in its personal lines business, covering products such as home, car, pet, travel, and other types of personal insurance. Allianz UK refused to comment on whether it was extorted by the criminals working for Clop, but said that it reported itself to the Information Commissioner's Office, although the watchdog did not respond to our efforts to verify this claim. The insurance giant also confirmed that the attack was entirely separate from an earlier breach at Allianz Life, one of its US subsidiaries, the majority of whose 1.4 million customers had their data compromised in July. It joins a long list of organizations to have been hit by Clop using the same EBS exploit, among which was the Washington Post, which confirmed a related attack on Thursday. American Airlines' subsidiary, Envoy Air, also confirmed it was among the bigger victims of Clop's EBS raids last month. Researchers at Google offered their view on the situation in early October, positing that "dozens" of organizations were likely affected, and that attacks exploiting CVE-2025-61882 (9.8) could have begun as early as July, three months before any detections were made public. "We're still assessing the scope of this incident, but we believe it affected dozens of organizations," John Hultquist, chief analyst at Google Threat Intelligence Group, told The Register at the time.  "Some historic Clop data extortion campaigns have had hundreds of victims. Unfortunately, large-scale zero-day campaigns like this are becoming a regular feature of cybercrime." Clop made a name for itself off the back of the supply chain attack on Progress' MOVEit MFT software – another zero-day attack in 2023 that has affected more than 95 million individuals and nearly 3,000 organizations to date.

Daily Brief Summary

DATA BREACH // Allianz UK Affected by Clop's Oracle E-Business Suite Data Breach

Allianz UK confirmed a data breach affecting 80 current and 670 former customers due to a Clop gang attack on its Oracle E-Business Suite.

The breach did not impact Liverpool Victoria (LV) or its systems, despite initial claims by the attackers.

Allianz UK has notified affected customers and reported the incident to the Information Commissioner's Office for further investigation.

The breach exploited a zero-day vulnerability in Oracle EBS, which is used for managing personal insurance lines like home and car insurance.

This incident is part of a broader campaign by Clop, which has targeted multiple organizations using the same vulnerability, including the Washington Post and Envoy Air.

Google Threat Intelligence Group suggests the attacks exploiting CVE-2025-61882 began as early as July, affecting potentially dozens of organizations.

Clop's previous exploits include the MOVEit MFT software attack, impacting millions and highlighting the growing threat of large-scale zero-day campaigns.