Thousands of employees exposed as Korean Air compromised in Oracle breach

  • Korean Air lost data on ~30,000 employees in KC&D supply-chain breach
  • Cl0p ransomware group leaked 500 GB archives, exposing names and bank account numbers
  • Incident mirrors 2023 MOVEit attack; dozens of global firms confirmed breached through EBS

South Korean airline Korean Air reportedly lost sensitive data on tens of thousands of its employees after a supply-chain attack on a catering company.

Local media are reporting that Korean Air Catering & Duty-Free (KC&D), a company that prepares in-flight meals for multiple airlines, and operates duty-free retail sales for passengers, was using Oracle E-Business Suite (EBS) at the time when the tool carried a critical-severity vulnerability.

The bug, tracked as CVE-2025-61882, was discovered in early October this year, when some companies started receiving emails from hackers claiming to have used it to break in and steal data.

Cl0p takes the blame

Oracle quickly released a fix, but the damage was already done. Ransomware operators Cl0p assumed responsibility for the attack, and in the weeks and months following the news, multiple high-level organizations confirmed falling victim to the attack.

Now, Korean Air has confirmed that in the supply-chain attack, it lost sensitive data on roughly 30,000 current and former employees. The compromised data includes full names and bank account numbers – leaving them at risk of identity theft and fraud. Other information, such as emails, phone numbers, or postal addresses, were apparently not compromised.

According to Security Week, Cl0p added KC&D to its site on November 21, leaking almost 500 GB of archives.

The Oracle E-Business Suite breach is similar in scope and damage as the 2023 MOVEit incident, in which hundreds of firms lost sensitive data on millions of people.

So far, there are dozens of confirmed breaches through EBS, including Envoy Air, Harvard University, University of Witwatersrand, Schneider Electric, Emerson, Cox Enterprises, Pan American Silver Corp, LKQ Corporation, GlobalLogic, Barts Health NHS Trust, and Dartmouth College.

Cl0p, widely considered to be a Russian‑nexus ransomware and extortion group, was also credited with the MOVEit attack. Its victims are counted in the dozens, and a few notable names include Shutterfly, Hatch Bank, Rubrik, Community Health Systems, Saks Fifth Avenue, and Procter & Gamble.

Via Security Week

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

I went to the woods to drink surprisingly great espresso

With summer's return, I'm again reminded of my limits as I head into the great outdoors: I can put up with a heavy, uncomfortable...

Cash App’s launching a phone service

Cash App's AT&T-based MVNO will offer an unlimited 5G data plan for $40 per month including taxes and fees. The new mobile service...

With the World Cup looming, there’s still no clear replacement for sports Twitter

Jayden Nelson of Canada celebrates 2-0 during the International Friendly match between Canada v Uzbekistan at the Commonwealth Stadium on June 1, 2026, in...

The Weather Channel app now predicts bad allergy days

The Weather Company announced an "enhanced allergy experience" now available through its The Weather Channel app designed to help allergy sufferers better understand when...

The Nintendo Switch 2 is $15 off at Woot

The Switch 2 is still setting sales records. | Image: The Verge, Nintendo Woot is hosting a small, but welcome deal on the Nintendo Switch...

Is Apple TV the new HBO?

This is Lowpass by Janko Roettgers, a newsletter on the ever-evolving intersection of tech and entertainment, syndicated just for The Verge subscribers once a...

Elon Musk is encouraging race riots on the eve of SpaceX’s IPO

Elon Musk, on the verge of becoming the world's first trillionaire, is whipping up anti-immigration tensions amid ongoing riots in Belfast, Northern Ireland. Following...

I’ve found the Goldilocks of portable MIDI controllers

I have tested more portable MIDI controllers than I can keep track of, and I will tell you right now: 37 keys is the...

Waymo introduces $30-a-month premium tier for riders who want faster pickups

Uber One, meet Waymo Premier. The robotaxi operator announced a new $29.99-a-month premium tier for riders who want a more elevated and exclusive autonomous...

A warrantless wiretap law is about to expire — but surveillance networks aren’t actually ‘going dark’

Congress has failed to pass a three-week extension of Section 702 of the Foreign Intelligence Surveillance Act (FISA), with the House voting 218-198 against...