SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach BARTS-HEALTH-NHS 2026-08-17

Barts Health NHS Trust: Clop Data Theft via Oracle E-Business Suite Zero-Day

"Barts Health NHS Trust, one of the largest NHS trusts in England, has had patient and financial data published on the Clop ransomware group's dark web leak portal following exploitation of a zero-day flaw in Oracle…"

Barts Health NHS Trust, one of the largest NHS trusts in England, has had patient and financial data published on the Clop ransomware group's dark web leak portal following exploitation of a zero-day flaw in Oracle E-Business Suite. Reporting on the Barts incident in our source set comes from a single OTHER-tier outlet (tarotnorge.com), which says the trust has confirmed the theft and is pursuing a High Court order to restrain publication of the leaked files. No victim statement, ICO filing, or national CERT advisory covering Barts specifically appears among the sources reviewed here, and no record count for the Barts breach has been reported in any of them. Readers should treat the trust-specific details below as single-sourced pending direct confirmation from Barts Health or the Information Commissioner's Office.

What is far better corroborated is the campaign around it. Multiple established outlets, including BleepingComputer and Computer Weekly, place the Barts-style intrusion inside the mass exploitation of CVE-2025-61882, a remote code execution flaw in Oracle EBS that Clop worked as a zero-day from early August 2025 and that Oracle patched in October 2025.

What Happened

According to tarotnorge.com, attackers exploited a vulnerability in Barts Health's Oracle E-Business Suite deployment and exfiltrated finance and billing records. The trust is reported to have said the theft occurred in August, but that it did not realise the data was at risk until November, when files surfaced on Clop's extortion site. The source does not state the year for either date; the timeline is consistent with the August 2025 zero-day window and the autumn 2025 leak-site postings described by other outlets, but that alignment is inference, not confirmation.

The blast radius is not confined to Barts itself. The same report says the stolen material covers accounting services Barts has provided since April 2024 to Barking, Havering and Redbridge University Hospitals NHS Trust, meaning a second trust's data is implicated through a shared back-office function. Barts Health runs five London hospitals: Mile End, Newham University, the Royal London, St Bartholomew's, and Whipps Cross University.

The trust is reported to be seeking a High Court order barring publication, use, or sharing of the exposed data. As tarotnorge.com itself notes, such orders have limited practical effect against an extortion crew operating Tor infrastructure from outside UK jurisdiction.

The wider victim list attributed to the Oracle EBS campaign in that report includes Envoy Air, Harvard University, GlobalLogic, The Washington Post, Logitech, Dartmouth College and the University of Pennsylvania. Separately and independently confirmed, Estée Lauder disclosed in July 2026 that an unauthorised third party accessed its EBS system on or around 9 August 2025, a date BleepingComputer explicitly correlates with the CVE-2025-61882 mass exploitation.

What Was Taken

For Barts Health, the reported categories are financial and administrative rather than clinical:

No volume figure has been reported. Nothing in the sources indicates medical records or full clinical histories were taken, and the "patient data" framing rests on billing records that identify people as having received private or chargeable care at named hospitals. That is a meaningful sensitivity in its own right: an invoice from St Bartholomew's, a specialist cardiac and cancer centre, is close to a diagnosis by inference.

The Estée Lauder disclosure shows what the same intrusion vector yields when it lands on an HR-configured EBS instance. Both BleepingComputer and Computer Weekly list full names, postal and email addresses, dates of birth, US Social Security numbers, passport numbers, bank account details, health information, and employment data including payroll and performance reviews. The two outlets agree closely on the field list; Computer Weekly adds that Estée Lauder has neither confirmed nor denied Clop involvement or any ransomware component. Estée Lauder identified the intrusion in June 2026, roughly ten months after the 9 August 2025 access date, a lag comparable to the August-to-November gap reported at Barts.

Why It Matters

Three things make this brief worth a defender's attention beyond the headline.

First, dwell-and-discovery time is the actual failure. Barts is reported to have learned of the theft only when Clop published. Estée Lauder took until June 2026 to determine what happened on 9 August 2025. In both cases the extortion site, not internal telemetry, was the detection mechanism. An organisation that finds out from the leak site has no window to notify, contain, or negotiate.

Second, shared services multiply the victim count silently. Barts processing accounts for Barking, Havering and Redbridge means one compromised ERP instance exposes two trusts. The same pattern shows up elsewhere in the UK sector: Infosecurity Magazine reported in August 2026 that around 1,500 UK charities, including healthcare and victim support organisations, potentially suffered breaches through a single compromised CRM provider, Beacon. Concentration risk in back-office platforms is now a primary determinant of breach scale.

Third, NHS operational fragility compounds the security problem. FOI data analysed by Dynatrace and reported by healthtechdigital.com found five of the UK's largest trusts, Barts among them, plus NHS England logged 274,620 IT incidents across 2025, with the analysis noting that inconsistent recording means the real figure is likely higher. The same dataset shows 14,287 operations and appointments cancelled or moved in a single day, 3 June 2024, during the Synnovis ransomware attack. This is an OTHER-tier source promoting a vendor's own analysis and should be read with that in mind, but the direction is consistent with the sector's public record.

The NHS also has a demonstrated data-handling problem independent of any attacker. The BBC reported on 14 August 2026 that NHS Blood and Transplant had routinely sent transplant patients' names, dates of birth and organ types across an unencrypted pager network, has apologised, has reported itself to the Information Commissioner, and cannot determine how many people were affected because pager traffic leaves no delivery record. Different failure mode, same outcome: sensitive data outside the trust boundary with no way to scope the exposure.

The Attack Technique

CVE-2025-61882 is a remote code execution flaw in Oracle E-Business Suite. Per BleepingComputer, it affects EBS versions 12.2.3 through 12.2.14 and allows attackers to bypass authentication and execute code remotely through the BI Publisher Integration component. Google and Mandiant researchers warned in October 2025 that Clop was exploiting it as a zero-day for data theft; Oracle issued a patch that month. Computer Weekly notes that several flaws may have contributed to the wave of EBS breaches over roughly a three-month period, with CVE-2025-61882 the most prominent, and that early attribution chatter linking ShinyHunters-associated individuals to the exploit activity was not supported by sufficient evidence according to threat researchers.

The operational pattern is pure data-theft extortion rather than encryption. Clop steals, then mass-mails. Ransom-ISAC's Brandon Parsons told BleepingComputer that in Clop's current campaigns the extortion emails originate from apparently compromised third-party accounts, are blasted to hundreds of employees inside a target organisation, and carry Clop's latest contact details, an approach he described as consistent with what was observed during the Oracle EBS campaign.

That campaign is not the end of the pattern, it is one instance of it. Clop has since moved to PTC Windchill and FlexPLM, where ReliaQuest reported active exploitation of CVE-2026-12569, a critical unsafe deserialization flaw rated CVSS 9.3 enabling unauthenticated RCE and JSP webshell deployment for product data exfiltration. ReliaQuest stopped short of naming Clop, saying the actor "remains unconfirmed" while noting tradecraft overlap with prior Clop enterprise-application campaigns; Ransom-ISAC separately confirmed Clop involvement. Note the divergence: one researcher hedges attribution, one asserts it.

The adjacent case worth watching is Progress Software's ShareFile action of July 2026, reported by The Register. Progress told customers running on-premises ShareFile Storage Zone Controllers to manually power down the hosting Windows servers over a "credible external security threat", with no patch or workaround available, while simultaneously stating it had "no indication of unauthorized access to any ShareFile customer account or data" and had "not identified any active threat". Progress declined to answer The Register's questions about the nature of the threat, affected versions, or when systems could be restored. Progress is the vendor behind MOVEit Transfer, Clop's 2023 mass-exploitation target. No source in this set connects the ShareFile advisory to Clop or to the Barts breach, and it should not be assumed to be related. It is included here because the shape, managed file transfer and enterprise application platforms as the target class, is the shape of every campaign in this brief.

What Organizations Should Do

  1. Patch and audit Oracle EBS now, then assume prior compromise. If you run EBS 12.2.3 through 12.2.14, confirm the October 2025 fix for CVE-2025-61882 is applied. Patching does not evict an attacker who got in during the August-to-October 2025 window. Hunt retrospectively for webshells, anomalous BI Publisher activity, and unexplained outbound data volume across that period rather than treating the patch as closure.
  2. Get internet-facing ERP, PLM and MFT platforms off the open internet. Oracle EBS, PTC Windchill and FlexPLM, ShareFile Storage Zone Controllers, and the MOVEit-class systems before them all follow the same trajectory: internet-exposed, credential-optional, holding the entire finance or HR dataset. Put them behind VPN or identity-aware proxy and restrict administrative interfaces to known source ranges.
  3. Instrument for exfiltration, not just intrusion. In both Barts and Estée Lauder, the intrusion was invisible for months and the theft surfaced externally. Baseline normal egress from ERP and HR systems, alert on bulk table exports and off-hours large transfers, and make outbound volume a monitored signal rather than an incident-response artefact.
  4. Map and contract for shared-service exposure. Barts processes accounts for another trust; 1,500 charities were exposed through one CRM provider. Inventory every function you perform for a third party and every function performed for you, and make sure breach notification obligations flow in both directions before you need them.
  5. Rehearse the mass-extortion-email scenario. Clop mails hundreds of staff from compromised legitimate accounts. That means your first indication may arrive simultaneously in every inbox in the organisation. Pre-agree who speaks, what staff are told to do with the message, and how you distinguish the real extortion attempt from opportunistic copycats.
  6. Do not treat a court order as containment. Injunctions against a Tor-hosted leak site have, as the reporting on Barts itself acknowledges, limited practical effect. Notification, credential resets, fraud monitoring for affected individuals, and honest disclosure are the controls that actually reduce harm.
  7. Audit legacy transmission paths while you are in there. The NHSBT pager disclosure is a reminder that data leaves the perimeter through channels nobody has reviewed in a decade, and that untracked channels make scoping impossible after the fact.

Sources: Barts Health NHS Data Breach: Clop Ransomware Exploits Oracle Zero-... | Progress orders emergency ShareFile server shutdown ... | Cosmetics giant Estée Lauder victim of mass Oracle breach Computer... | Estée Lauder discloses data breach via Oracle E-Business flaw | NHS Blood and Transplant investigate data breach due to pager use -... | Healthcare and Victim Support Charities Affected by Beacon Cyber In... | Clop ransomware targets Windchill, FlexPLM in data theft ... | Digital resilience offers antidote to NHS IT outages currently disr...