Oracle Vulnerability Leads to Attack on NCH
Irving, Texas-based NCH Corporation, a maker of industrial maintenance, water treatment and lubricants, fell victim to a cyberattack via a third-party vendor where personally identifiable information ended up stolen in the hack.
“NCH like multiple other organizations use Oracle’s E-Business Suite (“EBS”) software to help manage their operations,” the company said in a notice to victims. “In August 2025, an unauthorized actor leveraged a previously unknown vulnerability in Oracle EBS to take information from numerous organizations’ Oracle EBS applications. NCH learned it was one of those organizations.”
Upon becoming aware of the incident, NCH immediately implemented its response procedures, took measures to secure its implementation of Oracle EBS, and launched an investigation with the support of third-party cybersecurity professionals. NCH also notified law enforcement and is supporting its investigation.
The evidence showed an unauthorized actor obtained files from the NCH Oracle EBS application in mid-August. NCH reviewed the files and, on November 25, determined one or more of the files contained the names, date of birth, Social Security numbers, and benefits enrollment information.
