Skip to main content
See every side of every news story
Published loading...Updated

Google Says Hackers Are Sending Extortion Emails to Executives

Mandiant and Google track a high-volume extortion email campaign potentially linked to Clop ransomware using hundreds of compromised accounts, with investigations ongoing.

  • On October 2, Google warned executives that extortion emails claim stolen sensitive data from Oracle E-Business Suite, a campaign Mandiant and GTIG say began on or before September 29, 2025.
  • Using hundreds of hijacked accounts, the campaign sent extortion emails with contact addresses listed on the Clop data leak site and at least one previously linked to a Cl0p affiliate.
  • Some messages demand up to $50 million, while Halcyon confirmed emails show screenshots and directories as proof, using sloppy English and urging contact via leak site addresses.
  • Investigators are working through the night to confirm access while experts warn unverified claims can destabilise businesses, and the U.S. State Department offers a $10 million reward for information linking Clop to a foreign government.
  • Since March 2019, the Clop ransomware operation compromised more than 3,000 US and 8,000 global organisations, with its 2023 MOVEit exploitation exposing data from more than 2,300 organisations.
Insights by Ground AI
Podcasts & Opinions

24 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 46% of the sources are Center, 46% of the sources lean Right
46% Right

Factuality 

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in on Wednesday, October 1, 2025.
Sources are mostly out of (0)
News
For You
Search
BlindspotLocal