SYS::ONLINE
Wasteland.
Briefs1223
Issues19
SinceFeb 2026
LIVE
█ Ransomware BARTS-HEALTH-NHS 2026-06-25

Barts Health NHS: Clop Ransomware via Oracle Zero-Day

"Barts Health NHS, one of England's largest healthcare providers, has confirmed a significant data breach after the Clop ransomware gang exploited a zero-day vulnerability in Oracle E-Business Suite software. The trust…"

Barts Health NHS, one of England's largest healthcare providers, has confirmed a significant data breach after the Clop ransomware gang exploited a zero-day vulnerability in Oracle E-Business Suite software. The trust, which operates five hospitals across London, disclosed that attackers stole files containing the personal information of patients, former employees, and suppliers. The intrusion occurred in August 2025 but the full scope was not understood until November, when stolen data began surfacing on the dark web. Barts has notified the National Cyber Security Centre (NCSC) and the Information Commissioner's Office (ICO).

What Happened

The Clop ransomware gang infiltrated Barts Health systems by exploiting a critical flaw in Oracle's E-Business Suite (EBS) software, tracked as CVE-2025-61882. The group exfiltrated files containing years of invoice records and personal data rather than relying solely on traditional file encryption, consistent with Clop's known data-theft-and-extortion model.

The compromise began in August 2025, but it took until November for Barts to grasp the full extent of what had been taken. By that point, Clop had already begun leaking the stolen information on its dark web leak site. The trust has acknowledged the theft and is pursuing legal action to prevent further publication or sharing of the exposed data, though the practical impact of such measures against a criminal group operating in this manner is limited.

Notably, the compromised database did not only hold Barts' own records. It also contained sensitive information tied to accounting services that Barts provided to another NHS trust, extending the blast radius of the incident beyond a single organization.

What Was Taken

The stolen files include invoices spanning multiple years, exposing the full names and addresses of individuals who sought treatment or services at Barts Health hospitals. The breach also reached beyond current patients:

Barts Health has stated that the attack did not compromise patient medical records or clinical systems, and that the exposed data is administrative and financial in nature. While that distinction matters, names, addresses, and billing details are more than sufficient to fuel convincing phishing, fraud, and social engineering campaigns against affected individuals.

Why It Matters

This incident underscores how a single unpatched zero-day in widely deployed enterprise software can cascade across multiple organizations. Oracle E-Business Suite is a backbone application for finance, procurement, and HR functions in countless large institutions, making it a high-value target for mass-exploitation campaigns.

Barts is far from alone. The same Clop campaign against CVE-2025-61882 has reportedly claimed victims including Envoy Air, Harvard University, and a range of educational and media institutions worldwide. For defenders, the takeaway is that supplier and shared-service relationships expand exposure: when one organization provides accounting or IT services to another, a breach at the provider becomes a breach at the customer. Healthcare providers, which hold uniquely sensitive data and operate sprawling vendor ecosystems, sit squarely in the crosshairs of this kind of opportunistic, vulnerability-driven extortion.

The Attack Technique

Clop has been exploiting CVE-2025-61882, a critical zero-day vulnerability in Oracle E-Business Suite, since early August 2025. The flaw allowed the group to access and exfiltrate private data from internet-facing EBS deployments before a patch was widely applied. Rather than detonating ransomware to encrypt systems, Clop favored a steal-and-extort approach, quietly pulling files and then pressuring victims through public leak threats.

This pattern mirrors Clop's previous mass-exploitation campaigns against managed file transfer and enterprise platforms, where the group weaponizes a single zero-day across hundreds of organizations simultaneously, then works through the stolen data over weeks and months. The gap between the August intrusion at Barts and the November discovery is characteristic of this slow-burn extortion model, where dwell time is high and detection often comes only after data appears publicly.

What Organizations Should Do

Sources: Barts Health NHS Data Breach: Oracle Zero-Day Hack & Ransomware Attack (2026)

TWEET: Barts Health NHS breached by Clop ransomware via Oracle EBS zero-day (CVE-2025-61882). Patient, staff & supplier data leaked on the dark web. Full breakdown: https://wasteland.me/intel/barts-health-nhs-oracle-zero-day-ransomware #CyberSecurity #ThreatIntel