Bimbo Bakeries USA — the American arm of Grupo Bimbo, the world's largest baking company — has confirmed a data breach in which attackers stole employee names and Social Security numbers by exploiting a critical zero-day vulnerability in Oracle's E-Business Suite, joining a growing roster of organisations victimised by the Clop ransomware gang's sustained global campaign against Oracle EBS customers. The breach was disclosed in a notification letter dated August 31, 2026, filed with the California Attorney General's office on September 4, 2026, nearly a year after the underlying intrusion first occurred.
While Bimbo Bakeries did not name the specific vulnerability in its notification letter, the timeline, vendor profile, and attack methodology precisely match CVE-2025-61882 — a critical unauthenticated remote code execution flaw in the BI Publisher Integration component of Oracle EBS's Concurrent Processing module. The vulnerability carries a CVSS score of 9.8 and allowed attackers to execute arbitrary code on vulnerable Oracle EBS servers without requiring any valid credentials. Google-owned Mandiant traced active exploitation of this zero-day back to August 2025 — weeks before Oracle issued an emergency patch on October 4, 2025 — confirming that attackers had a significant head start against unpatched systems. CISA subsequently added CVE-2025-61882 to its Known Exploited Vulnerabilities catalog following Oracle's disclosure. Researchers at Mandiant and other cybersecurity firms attributed the campaign to the Clop extortion group, which systematically targeted Oracle EBS customers across multiple industries and geographies, stealing data and leveraging it for ransom demands. Other confirmed victims of the same campaign include Harvard University and The Washington Post — confirming the scope and ambition of the operation.
The breach did not originate directly from Bimbo Bakeries' own internal systems. Instead, it traced to a third-party vendor that relied on Oracle EBS for business operations and gave Clop's operators the access point they needed. This third-party entry vector is characteristic of the Clop group's methodology — rather than targeting an organisation's hardened internal perimeter, attackers identify a widely used vendor platform, exploit a single critical vulnerability in it, and gain simultaneous access to data belonging to multiple organisations that use or share that platform. Bimbo Bakeries' investigation determined on December 6, 2025, that the zero-day had been exploited to acquire files from within the Oracle EBS environment. The company applied Oracle's emergency patches as soon as it became aware of the flaw and launched an internal forensic investigation to determine exactly which data had been exposed.
The months-long gap between the December 2025 discovery and the September 2026 notification reflects the forensic complexity of identifying what was contained within files exfiltrated from a large enterprise ERP platform. The investigation did not confirm the presence of sensitive personal data until August 19, 2026 — the point at which forensic review of the stolen files identified a specific file containing affected individuals' full names and Social Security numbers. Under US state breach disclosure laws, formal notification obligations are triggered by the identification of specific sensitive data categories rather than by the initial discovery of unauthorised access. Once the August 19 confirmation was made, Bimbo Bakeries proceeded with breach notifications and filed with the California Attorney General's office on September 4.
The confirmed data categories — full names and Social Security numbers — form one of the most dangerous combinations in identity theft. Unlike a stolen password, a Social Security number cannot be reset or changed, and its combination with a verified full name provides attackers with everything necessary to file fraudulent tax returns, open new credit accounts, apply for loans, or build a more detailed victim profile by combining it with other publicly available information. Although the notification does not specify whether affected individuals are current or former employees, the nature of Oracle EBS as an enterprise HR and payroll platform suggests the exposed data belonged to people with an employment or business relationship with the company. Bimbo Bakeries has not publicly disclosed the total number of individuals affected.
Bimbo Bakeries USA has expressed regret over the incident and stated that it is re-evaluating its vendor relationships to reduce the risk of similar third-party supply chain compromises in the future. Affected individuals are being offered 12 months of single-bureau credit monitoring, a single-bureau credit report, and a single-bureau credit score service, along with proactive fraud remediation assistance through Cyberscout, a TransUnion company. Affected individuals are strongly advised to enrol in the offered monitoring services immediately, place a credit freeze with all three major credit bureaus — Equifax, Experian, and TransUnion — to prevent unauthorised credit applications, monitor financial accounts and tax filing records for suspicious activity, and be highly vigilant against phishing attempts that may reference verified personal details from the breach to create a false sense of legitimacy.