Cybersecurity events of November at a glance

November 2025 was marked by high-volume targeted campaigns. While the global volume of ransomware attacks dipped slightly to 659 incidents (-5%), the severity of data theft increased drastically. The month was dominated by the Qilin (107 claims) and Akira groups, and a critical Zero-Day in Oracle E-Business Suite (CVE-2025-61882).

In France, despite a drop in volume, the impact was severe with major breaches at Eurofiber and the FFF, exposing millions of citizens. Internationally, the focus remains on supply chain vulnerabilities and massive social engineering campaigns.

Key events of the month

🇫🇷 France: Supply Chain & Personal Data

  • Eurofiber & Third-Party Risk (Nov 13): The operator confirmed a breach via a vulnerability in its ticketing portal. Before patching, data was exfiltrated from high-profile clients including Thales, TotalEnergies, and SNCF. This highlights the critical risk of unmonitored B2B portals.
  • FFF / French Football Federation (Nov 20): The French Football Federation’s platform was hacked, leaking the personal data (licenses, addresses, emails) of millions of amateur players. Expect a surge in targeted phishing campaigns against these individuals.
  • Industrial Targets: The Qilin group claimed responsibility for attacks on Prova (manufacturing) and France Terre d’Asile, while Colis Privé suffered a customer contact theft by local threat actors late in the month.

🇺🇸 United States: The Oracle Zero-Day Wave

The exploitation of the Oracle E-Business Suite Zero-Day (CVE-2025-61882) by the Clop gang caused widespread damage in November (relating to intrusions from July-August):

  • University of Pennsylvania: 1.2M records exposed via SSO.
  • Corporate Giants: breaches confirmed at The Washington Post (financials), Cox Enterprises, and GlobalLogic.
  • DoorDash (Social Engineering): A massive exposure of customer contacts stemming from a sophisticated employee scam on October 25.

🌍 International: DeFi and Infrastructure

  • Record Exfiltration: Qilin led the charts with 31,200TB of data claimed exfiltrated globally.
  • Critical Infrastructure: Sweden’s Miljödata (1.5M victims) and Italy’s Almaviva were hit.
  • Finance: The Balancer DeFi protocol suffered a $120M loss due to a smart contract exploit.

Observed trends

  1. Extortion

    A brutal paradigm shift. With 31,200 TB exfiltrated by Qilin alone, attackers are no longer just seeking to paralyze your operations, but to monetize your secrets. Encryption is becoming secondary: the real weapon is now the threat of disclosure.

2. Sector Shifts

  • Healthcare: +43% (20 attacks).
  • Manufacturing: +35% (166 attacks) – the most targeted sector.
  • Education: +24% (21 attacks).

3. The “Portal” Vector

The Eurofiber and DoorDash incidents prove that web portals and helpdesk tools are the new weak entry points. Whether through technical flaws (Oracle) or social engineering, attackers are bypassing traditional perimeter defenses.

Technical watchpoints

  • Oracle E-Business Suite: Immediate patching of CVE-2025-61882 (versions 12.2.3 to 12.2.14) is mandatory to stop Clop RCE attacks.
  • Portals & SSO: Following the UPenn and Eurofiber breaches, conduct immediate vulnerability scans on all external-facing portals and enforce strict MFA.
  • Backup Segmentation: With Qilin and Akira targeting edge devices, ensure backups are immutable and segmented from the main network.

Recommendations for CTOs and CISOs

  • Audit Third-Party Access: Do not trust external portals blindly. Implement “Zero Trust” policies for all B2B connections.
  • Patch & Test: Accelerate the patching cycle for critical ERPs (Oracle), but include rigorous regression testing.
  • Anti-Phishing Drills: With the FFF and DoorDash leaks, employees are prime targets. Isolate their web browsing to neutralize malicious links.

Where Reemo makes a difference

In a landscape dominated by portal vulnerabilities and credential theft, Reemo provides a decisive layer of defense:

  • Remote Browser Isolation (RBI): Neutralizes the threat of phishing and social engineering (like the DoorDash case) by executing web content in a disposable container, keeping threats away from the endpoint.
  • Reemo Bastion+: Secures third-party access (crucial for cases like Eurofiber). It offers Just-in-Time privileged access and full session traceability, ensuring no unmonitored activity occurs on your critical systems.
  • Application Isolation: Prevents lateral movement. Even if an initial entry point is compromised (like an Oracle server), Reemo limits the attacker’s ability to jump to other segments of the network.

Book a demo of Reemo – Réservez une démo de Reemo

Leave a Reply

Trending

Discover more from Reemo blog

Subscribe now to keep reading and get access to the full archive.

Continue reading