Bimbo Bakeries USA data breach exposes Social Security numbers
Bimbo Bakeries USA says attackers stole a file with employee names and Social Security numbers after breaking into a vendor's Oracle business software through an unpatched flaw. The company confirmed the break-in months earlier but did not realize Social Security numbers were in the stolen file until August 2026.
- Report priority
- High
- Victim
- Bimbo Bakeries USA
What is known
- A third-party vendor that handles Bimbo Bakeries USA employee data ran its systems on Oracle E-Business Suite, a back-office platform used for HR and finance records.
- Attackers exploited a zero-day flaw in that software, consistent with CVE-2025-61882, that let them run their own code without logging in.
- Google's threat researchers found attackers sending a rigged web request to the software's SyncServlet component, then creating and running a disguised report template to gain control and pull data out.
- Oracle did not release a fix until October 2025, but the attacks likely began around August 2025, before any patch existed.
- Once inside, the attackers copied files out of the vendor's Oracle system; BBU has not said whether they reached any other systems.
- BBU finished investigating in December 2025 but did not discover Social Security numbers in one of the stolen files until August 19, 2026.
What to do
If you are a current or former BBU employee who received, or receives, a written notice dated around August 31, 2026, about this incident, check your installed release against the 12.2.3 to 12.2.14 range and confirm whether the emergency patch for CVE-2025-61882, plus its prerequisite Critical Patch Updates, has been applied.
BBU is offering affected individuals 12 months of single-bureau credit monitoring, credit reports, credit score tracking, and fraud assistance through Cyberscout. Enroll using the instructions in the notice, watch account and credit activity, and consider a fraud alert or credit freeze. Oracle E-Business Suite operators should not treat patching alone as complete remediation: apply Oracle's emergency fix and prerequisite Critical Patch Updates, then review logs for SyncServlet, UiServlet, and TemplatePreviewPG requests and check the XDO_TEMPLATES_B and XDO_LOBS tables for unexpected templates, per Oracle and Google's guidance.
Reported details
Google's Threat Intelligence Group documented attackers sending a POST request to the Oracle E-Business Suite SyncServlet component, then creating a disguised report template (with a TemplateCode starting with TMP or DEF) and running it through Template Preview to execute code and pull data, backed by Java-based tools tracked as GOLDVEIN.JAVA and the SAGEGIFT, SAGELEAF, and SAGEWAVE chain.
The affected software is Oracle E-Business Suite (EBS), an on-premises enterprise system that stores payroll, HR, and other back-office records. The flaw, consistent with CVE-2025-61882, is an unauthenticated remote code execution bug in EBS versions 12.2.3 to 12.2.14, fixed by an Oracle emergency patch in October 2025. Google's Threat Intelligence Group says exploitation likely began around August 2025, using a request to the SyncServlet endpoint to create and run a malicious report template, followed by in-memory Java payloads (GOLDVEIN.JAVA, SAGEGIFT, SAGELEAF, SAGEWAVE). A large-scale extortion campaign associated with the CL0P brand has used this flaw, though branding alone does not confirm attribution, and BBU has not linked its incident to any group.