An Oracle flaw let attackers take Social Security numbers. Bimbo Bakeries confirmed it.
Bimbo Bakeries USA has confirmed that files holding names and Social Security numbers were taken out of its Oracle E-Business Suite environment, CyberInsider reported on Monday.
CyberInsider names the vulnerability used as CVE-2025-61882, an unauthenticated remote code execution flaw in the BI Publisher Integration component of Oracle E-Business Suite, rated 9.8 on the CVSS scale. Oracle published a patch and the company applied it.
Then read the dates in the filing. Bimbo Bakeries determined on 6 December 2025 that unauthorized parties had acquired files. It identified the file holding names and Social Security numbers on 19 August 2026. The letter to affected people went out on 31 August, and the notice reached the California Attorney General on 4 September.
From 6 December to 19 August is 256 days between knowing that something left and knowing what was in it.
The company has not said how many people are affected. It is offering 12 months of credit monitoring through Cyberscout. CyberInsider notes the Clop group has been tied to the wider Oracle E-Business Suite campaign, and that Bimbo Bakeries has not attributed this attack to anyone.
How long would it take you to say exactly which records left your own ERP?
Sources
Our file on Oracle
- 20 Sept
Oracle's data-centre lenders are stuck with $18 billion they cannot sell.
- 17 Sept
Oracle shipped 673 patches. Six maximum-severity flaws needed no login.
- 12 Sept
Oracle raised its layoff budget by $700 million to $2.8 billion.
- 9 Sept
Brussels settled with SAP. It is now asking about Oracle.
- 8 Sept
£19m budgeted. £216.5m lost.
Every story here is open to read. The ERP LEADERS brief goes one step further.
One ERP programme per issue, laid out for a steering committee. Issue 01 is the Zeiss case. Read issue 01 or sign up for the brief.
Welcome back. · Issue 01
