// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
Bimbo Bakeries USA confirmed a data breach through Oracle EBS with an eight-month gap between discovery and notification. The case highlights the limits of secondary sources on zero-day ERP compromises.

Disclaimer: No primary Oracle, CISA, or Mandiant source is available for this incident. The CVE-2025-61882 correlation is inferred from converging technical sources, not declared by Bimbo Bakeries. Information is based on secondary cybersecurity news sources.

Bimbo Bakeries USA notified a data breach on August 31, 2026, with discovery dated December 6, 2025. Confirmation of the theft of names and Social Security numbers arrived on August 19, 2026. The incident, traced to a third-party vendor using Oracle E-Business Suite, illustrates the gap between forensic discovery and notification in complex ERP environments.

Key Takeaways
  • Bimbo Bakeries confirmed the breach with a letter dated August 31, 2026, filed in California on September 4; the investigation required roughly eight months from December 6, 2025.
  • Converging technical sources identify the vulnerability as CVE-2025-61882, an unauthenticated RCE in the BI Publisher Integration component of Oracle EBS, with a CVSS score of 9.8.
  • Oracle released an emergency patch on October 4, 2025; CISA added the vulnerability to the KEV catalog; Mandiant tracked exploitation to at least August 2025.
  • Bimbo Bakeries has not publicly attributed the breach to Clop, has not disclosed the number of individuals affected, and has not confirmed extortion demands.

The Breach Chain: From Third-Party Vendor to Employee Data

The attack hit Bimbo Bakeries USA, producer of bread and snacks under brands such as Entenmann's, Sara Lee, and Thomas', through an external vendor managing Oracle E-Business Suite systems.

The company determined on December 6, 2025, that attackers had exploited a zero-day to exfiltrate files from the system. Only on August 19, 2026, after nearly eight months of forensic review, did Bimbo confirm that at least one of the stolen files contained names and Social Security numbers.

The notification, dated August 31, 2026, was filed with the California Attorney General's office on September 4. The company is offering 12 months of free credit monitoring through Cyberscout. It has not disclosed the number of individuals affected, nor clarified whether the data belongs to current employees, former employees, or other categories.

The Vulnerability: CVE-2025-61882 and Its Footprint

Converging technical sources identify the vulnerability as CVE-2025-61882, with a CVSS score of 9.8. It is an unauthenticated remote code execution flaw in the BI Publisher Integration component of Oracle E-Business Suite, versions 12.2.3 through 12.2.14. Oracle released an emergency patch on October 4, 2025. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog shortly after disclosure.

Mandiant, a Google company, tracked active exploitation to at least August 2025, weeks before the fix became available. This exposure window — at least two months between first documented exploitation and patch — shows the zero-day risk in ERP environments, where service interruption for emergency updates carries significant operational impact.

"hackers stole employee data by exploiting a zero-day vulnerability in Oracle's E-Business Suite (EBS), joining a growing list of organizations swept up in the Clop ransomware gang's global extortion campaign against Oracle customers"

Clop, the Campaign, and the Limits of Attribution

Security researchers have attributed the broader campaign to the Clop group, known for encryption-less extortion: it steals data, threatens publication, and does not deploy ransomware. Sources report other confirmed victims in the same cycle: Harvard University, The Washington Post, and University of Phoenix — the latter with 3.5 million individuals affected.

Bimbo Bakeries has not publicly attributed its breach to Clop, nor confirmed receiving extortion demands. Attribution remains, for this specific case, an analyst hypothesis not endorsed by the victim.

Immediate Actions

For organizations running Oracle EBS, converging sources indicate documented actions:

  • Verify application of the October 4, 2025 emergency patch for CVE-2025-61882 on versions 12.2.3-12.2.14.
  • Review access logs for the window documented by Mandiant, adapted to your operational context.
  • Reassess visibility into third-party vendors with access to ERP systems, in line with Bimbo Bakeries' statement on "re-evaluating its vendor relationships."
  • Monitor the CISA KEV catalog for Oracle vulnerability additions; CVE-2025-61882 received this designation.

ANALYSIS: The Delay Between Discovery and Notification

The following section is editorial analysis, not a fact verified by the brief.

Bimbo Bakeries' timeline — discovery December 6, 2025, PII confirmation August 19, 2026, notification August 31 — shows a recurring pattern in ERP breaches. Breach notification statutes demand speed, but the complexity of ERP systems with interconnected relational databases, dozens of tables, and payroll histories makes forensic analysis extensive. This creates tension between regulatory obligations and technical verification capacity.

The legal framework assumes linearity: discovery, verification, notification. ERP systems do not follow this model. "Discovery" of an intrusion does not equal "discovery" of which data was touched, nor to whom it belonged. Bimbo Bakeries took eight months to move from the first stage to the third.

The consequences for employees — whose Social Security numbers were exposed — depend not on notification speed but on response quality. The offer of 12 months of credit monitoring is the industry standard; the source does not specify additional measures.

Information is based on converging secondary sources, in the absence of a primary advisory, and current as of publication.

Information has been verified against cited sources and updated as of publication.

Sources


Sources and references
  1. cybersecuritynews.com
  2. cyberinsider.com
  3. databreachrights.com
  4. simplysecuregroup.com
  5. underdefense.com