
Bimbo Bakeries USA has disclosed a data breach caused by the exploitation of an Oracle E-Business Suite (EBS) zero-day that allowed attackers to steal files containing names and Social Security numbers.
The company says it determined on December 6, 2025, that unauthorized parties had acquired files stored in its Oracle EBS environment. However, it was not until August 19, 2026, that a review of the stolen data identified a file containing victims' names and Social Security numbers.
Bimbo Bakeries disclosed the incident in an August 31 notification letter and filed the notice on September 4.
According to the company, it applied patches released by Oracle after learning about the zero-day and launched an investigation that confirmed attackers had used the vulnerability to obtain files from its EBS application.
Bimbo Bakeries USA is one of the largest commercial baking companies in the United States and operates brands including Thomas', Entenmann's, Sara Lee, Ball Park, Arnold, Brownberry, and Oroweat.
The disclosure links the company to the broader Oracle EBS exploitation campaign that began in August 2025. The Clop ransomware group was previously tied to attacks exploiting multiple Oracle EBS vulnerabilities, including the critical CVE-2025-61882 zero-day.
The flaw, rated 9.8 on the CVSS scale, can allow unauthenticated remote code execution through Oracle EBS's BI Publisher component. Oracle EBS is widely used by large organizations for finance, human resources, procurement, and other internal operations, making compromised systems a valuable source of sensitive corporate and employee data.
Bimbo Bakeries has not attributed the attack to Clop, disclosed when the intrusion occurred, or said whether it received an extortion demand. The company also has not revealed the total number of affected individuals.
The incident follows other breaches tied to the same Oracle EBS campaign. In December 2025, the University of Phoenix disclosed that attackers stole data belonging to nearly 3.5 million people, including Social Security numbers and bank account information.
Bimbo Bakeries says it is re-evaluating its vendor relationships and is offering affected individuals 12 months of free single-bureau credit monitoring and fraud assistance through Cyberscout.
Because Social Security numbers were exposed, affected individuals should consider placing security freezes with Equifax, Experian, and TransUnion and monitor their financial accounts and credit reports for unauthorized activity. They should also remain alert for phishing attempts that use stolen personal information to make messages appear more convincing.







Leave a Reply