
GlobalLogic reported that in October, cyber criminals exploited a zero-day vulnerability in Oracle E-Business Suite, compromising the personal information of over 10,000 employees.
GlobalLogic, part of the Hitachi Group, is a global digital engineering firm that designs and builds products, platforms, and experiences for industries such as automotive, healthcare, and finance.
In a data security incident notice filed with the Office of Maine Attorney General, GlobalLogic said that on October 4, following Oracle’s security advisory regarding a previously undisclosed zero-day vulnerability in Oracle E-Business Suite, the company initiated an investigation—supported by external cybersecurity experts—to assess the extent of the incident.
“GlobalLogic’s investigation identified access to Oracle and exfiltration on October 9, 2025. We then began drafting and sending out notifications. The investigation has identified the earliest date of threat actor activity as July 10, 2025, with the most recent activity occurring on August 20, 2025,” the company said.
The compromised data included names, addresses, phone numbers, emergency contact information, email addresses, dates of birth, nationality, country of birth, passport information, internal GlobalLogic employee numbers, national identifiers or tax identifier including Social Security Numbers, salary information, bank account information, and routing numbers.
The filing with the Maine state regulator’s office also states that GlobalLogic has identified at least 10,471 individuals affected by the incident.
“In response to the incident, GlobalLogic promptly applied software patches upon their release from Oracle to its customers to address the vulnerability. Third party forensic experts were retained to investigate further.
“In addition, GlobalLogic reported this incident to law enforcement. This notice has not been delayed by law enforcement. This incident resulted from a zero-day vulnerability in our vendor’s software and we have taken all of the vendor’s recommended steps and also taken additional steps to enhance our security,” GlobalLogic added.
The company has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered two years of complimentary identity protection and credit monitoring services through Cyberscout to all affected individuals.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543