Barts Health NHS, one of England's largest healthcare providers, has confirmed a significant data breach after the Clop ransomware gang exploited a zero-day vulnerability in Oracle E-Business Suite software. The trust, which operates five hospitals across London, disclosed that attackers stole files containing the personal information of patients, former employees, and suppliers. The intrusion occurred in August 2025 but the full scope was not understood until November, when stolen data began surfacing on the dark web. Barts has notified the National Cyber Security Centre (NCSC) and the Information Commissioner's Office (ICO).
What Happened
The Clop ransomware gang infiltrated Barts Health systems by exploiting a critical flaw in Oracle's E-Business Suite (EBS) software, tracked as CVE-2025-61882. The group exfiltrated files containing years of invoice records and personal data rather than relying solely on traditional file encryption, consistent with Clop's known data-theft-and-extortion model.
The compromise began in August 2025, but it took until November for Barts to grasp the full extent of what had been taken. By that point, Clop had already begun leaking the stolen information on its dark web leak site. The trust has acknowledged the theft and is pursuing legal action to prevent further publication or sharing of the exposed data, though the practical impact of such measures against a criminal group operating in this manner is limited.
Notably, the compromised database did not only hold Barts' own records. It also contained sensitive information tied to accounting services that Barts provided to another NHS trust, extending the blast radius of the incident beyond a single organization.
What Was Taken
The stolen files include invoices spanning multiple years, exposing the full names and addresses of individuals who sought treatment or services at Barts Health hospitals. The breach also reached beyond current patients:
- Personal data of former employees
- Information relating to suppliers and third-party vendors
- Financial and accounting records connected to a second NHS trust serviced by Barts
Barts Health has stated that the attack did not compromise patient medical records or clinical systems, and that the exposed data is administrative and financial in nature. While that distinction matters, names, addresses, and billing details are more than sufficient to fuel convincing phishing, fraud, and social engineering campaigns against affected individuals.
Why It Matters
This incident underscores how a single unpatched zero-day in widely deployed enterprise software can cascade across multiple organizations. Oracle E-Business Suite is a backbone application for finance, procurement, and HR functions in countless large institutions, making it a high-value target for mass-exploitation campaigns.
Barts is far from alone. The same Clop campaign against CVE-2025-61882 has reportedly claimed victims including Envoy Air, Harvard University, and a range of educational and media institutions worldwide. For defenders, the takeaway is that supplier and shared-service relationships expand exposure: when one organization provides accounting or IT services to another, a breach at the provider becomes a breach at the customer. Healthcare providers, which hold uniquely sensitive data and operate sprawling vendor ecosystems, sit squarely in the crosshairs of this kind of opportunistic, vulnerability-driven extortion.
The Attack Technique
Clop has been exploiting CVE-2025-61882, a critical zero-day vulnerability in Oracle E-Business Suite, since early August 2025. The flaw allowed the group to access and exfiltrate private data from internet-facing EBS deployments before a patch was widely applied. Rather than detonating ransomware to encrypt systems, Clop favored a steal-and-extort approach, quietly pulling files and then pressuring victims through public leak threats.
This pattern mirrors Clop's previous mass-exploitation campaigns against managed file transfer and enterprise platforms, where the group weaponizes a single zero-day across hundreds of organizations simultaneously, then works through the stolen data over weeks and months. The gap between the August intrusion at Barts and the November discovery is characteristic of this slow-burn extortion model, where dwell time is high and detection often comes only after data appears publicly.
What Organizations Should Do
- Patch CVE-2025-61882 immediately. Apply Oracle's security updates for E-Business Suite and verify that internet-facing EBS instances are remediated and not still exposed.
- Hunt for prior compromise. Assume exploitation may predate patching; review logs for unusual EBS access, data staging, and large outbound transfers dating back to early August 2025.
- Reduce exposure of enterprise apps. Remove Oracle EBS and similar back-office systems from direct internet exposure, placing them behind VPNs or zero-trust access controls.
- Map third-party and shared-service risk. Identify where you provide or consume managed services (accounting, IT, payroll) and confirm partners have patched and assessed their own exposure.
- Strengthen exfiltration detection. Deploy data loss prevention and egress monitoring to flag bulk file movement, since Clop's model relies on theft rather than noisy encryption.
- Prepare affected-party communications. For breached organizations, notify regulators promptly and warn patients, staff, and suppliers to be vigilant against unsolicited messages requesting payments or sensitive information.
Sources: Barts Health NHS Data Breach: Oracle Zero-Day Hack & Ransomware Attack (2026)
TWEET: Barts Health NHS breached by Clop ransomware via Oracle EBS zero-day (CVE-2025-61882). Patient, staff & supplier data leaked on the dark web. Full breakdown: https://wasteland.me/intel/barts-health-nhs-oracle-zero-day-ransomware #CyberSecurity #ThreatIntel