A ransomware gang called Cl0p has spent August working through a fresh wave of victims, and the list keeps growing: energy giant Shell, healthcare firm Philips, and dozens of others across multiple sectors, with the group claiming close to 50 organisations in total. Closer to home, Barts Health, one of England’s largest NHS trusts, has confirmed that patient and staff data was affected by the same campaign. The common thread isn’t a shared supplier or a phishing email that fooled everyone at once. It’s a single software flaw, in Oracle’s E-Business Suite, that Cl0p appears to have been quietly exploiting since as early as last August, well before anyone knew it existed.

This is a different shape of risk to most of the breaches that make the news. Nobody at Shell or Barts Health clicked the wrong link or reused a weak password. Their organisations ran a piece of enterprise software that had a hole in it nobody had found yet, and one group found it, then worked through every organisation running that same software before anyone could patch it. Oracle has since confirmed the flaw and issued fixes, but for the organisations already on Cl0p’s list, that’s after the fact.

Cl0p isn’t new to this playbook. The same group has run near-identical campaigns against other widely used enterprise software in previous years, each time picking off dozens or hundreds of organisations that had no idea they were vulnerable until the group told them, usually by adding their name to a public leak site. The pattern is consistent: find one flaw in something thousands of organisations run, exploit it quietly and broadly for as long as possible, then extort everyone on the list at once once the game is up.

Why this matters if you’re nowhere near Oracle’s scale

Most UK SMEs don’t run Oracle E-Business Suite, but almost every business runs some piece of shared software: a CRM, an accounting package, a booking system, an e-commerce platform. The lesson from this wave isn’t “avoid big enterprise software.” It’s that any software your business depends on can have a flaw discovered and exploited at scale before you, or often the vendor, know it exists. Scale actually cuts the other way for a small business here: fewer systems means fewer places a flaw like this can hide, but it also means fewer resources to catch it fast when one does.

What smaller businesses can realistically do

Know what you’re actually running. A simple list of the software your business depends on, and who’s responsible for patching each one, sounds basic but is genuinely rare in small businesses. You can’t respond to “the vendor you use has a critical flaw” news if you don’t know your own software stack.

Turn on automatic updates wherever you safely can. Most of these mass-exploitation campaigns target unpatched systems, sometimes for months after a fix already exists. The gap between “patch available” and “patch applied” is where the damage happens.

Get proactive monitoring rather than waiting for the headline. By the time a breach like this makes the news, the exploitation has often been running for months. KeepSafe monitors for exactly this kind of incident affecting the software and suppliers your business actually relies on, so you find out early rather than by accident.

Ask your software vendors how they handle disclosure. A vendor that patches quickly and tells customers plainly what happened is a very different risk to one that stays quiet. It’s a fair question to ask before you commit to a platform, not just after something goes wrong with it.

The takeaway

Shell and an NHS trust getting caught up in the same breach shows that size doesn’t protect you from this particular risk, and diligence at the point of use doesn’t either. What protects you is knowing what software you depend on and patching it fast when a fix appears. That’s a habit any size of business can build, starting today.