$ techbeacon▋
CVE & Exploits

Bimbo Bakeries USA Discloses Zero-Day Hack That Exposed Social Security Numbers

Bimbo Bakeries USA Discloses Zero-Day Hack That Exposed Social Security Numbers

Bimbo Bakeries USA, the U.S. arm of the world’s largest bakery, announced that a cyberattack succeeded in extracting files that listed individuals' names alongside their Social Security numbers. The intrusion was traced to a previously unknown, or “zero‑day,” flaw in Oracle’s E‑Business Suite (EBS), a software platform that the company relies on through a third‑party service provider.

Oracle E‑Business Suite is a widely deployed enterprise resource planning (ERP) system that handles financial, procurement, and human‑resources functions for many large organizations. Because the vulnerability was unknown to both Oracle and its customers, no patch existed at the time of the breach, allowing attackers to move laterally within the network after gaining initial access.

According to the company’s statement, the compromised files contained personal identifiers, specifically names and Social Security numbers. The notice did not disclose the total number of records affected, but the inclusion of SSNs classifies the breach as a high‑impact incident under most data‑protection statutes.

Bimbo Bakeries USA said it immediately launched an internal investigation, engaged external cybersecurity experts, and informed federal and state law‑enforcement agencies. The firm also indicated that it is notifying affected individuals and is evaluating options for credit‑monitoring services, though no formal offer has been confirmed.

The breach triggers mandatory reporting obligations in several U.S. jurisdictions, and the company could face scrutiny from regulators such as the Federal Trade Commission, which enforces the Safeguards Rule for entities handling sensitive personal data. Industry observers note that supply‑chain software vulnerabilities have become a focal point for attackers seeking to compromise large enterprises indirectly.

Oracle has acknowledged the incident and is reportedly working on a fix for the exploited flaw. Security analysts recommend that organizations using E‑Business Suite audit their configurations, enforce strict access controls, and apply any forthcoming patches without delay. The episode underscores the growing risk that zero‑day exploits pose to businesses that depend on third‑party platforms for critical operations.

Source: GBHackers
Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related