Home
Finance
Travel
Shopping
Library
Create a Thread
Home
Discover
Spaces
 
 
  • Introduction
  • Oracle Cloud Breach Details
  • Oracle Health Data Compromise
  • Threat Actor 'rose87168' Actions
  • Oracle's Security Concerns
Oracle Suffers Multiple Data Breaches

According to recent reports, Oracle has faced two significant security breaches affecting its cloud infrastructure and health division, potentially exposing sensitive data of millions of users and patients across thousands of organizations.

User avatar
Curated by
editorique
3 min read
Published
14,106
489
bleepingcomputer.com favicon
BleepingComputer
Oracle customers confirm data stolen in alleged cloud breach is valid
bleepingcomputer.com favicon
BleepingComputer
Oracle Health breach compromises patient data at US hospitals
acaglobal.com favicon
ACACompliance
Six Million Records Potentially Compromised in Oracle Cloud Breach
gosecure.ai favicon
GoSecure
Oracle Cloud Breach: A Strategic Response to an Identity-Layer Threat
Oracle Headquarters
VCG
·
gettyimages.com
Oracle Cloud Breach Details

The alleged Oracle Cloud breach, discovered in March 2025, involved the exfiltration of approximately 6 million records affecting over 140,000 tenants1. The threat actor, known as "rose87168," claimed to have exploited a vulnerability (CVE-2021-35587) in Oracle's cloud login infrastructure, specifically targeting the endpoint login.(region-name).oraclecloud.com2. The compromised data reportedly includes Java Key Store (JKS) files, encrypted SSO and LDAP passwords, and Enterprise Manager JPS keys12. Despite Oracle's denial of the breach, multiple customers have confirmed to BleepingComputer that data samples shared by the attacker are valid3, and independent security researchers have corroborated the incident's authenticity45.

bleepingcomputer.com favicon
bleepingcomputer.com favicon
acaglobal.com favicon
20 sources
Oracle Health Data Compromise

The Oracle Health breach, disclosed in late March 2025, compromised patient data at multiple US healthcare organizations and hospitals. Oracle Health, formerly known as Cerner, became aware of unauthorized access to legacy Cerner data migration servers on February 20, 20251. The threat actor used compromised customer credentials to breach the servers sometime after January 22, 2025, and exfiltrated patient information from electronic health records1.

Oracle Health has not publicly disclosed the full extent of the breach, leaving affected healthcare providers responsible for determining HIPAA violations and patient notifications1. This incident highlights the ongoing security challenges faced by healthcare organizations transitioning to cloud-based systems and the potential risks associated with legacy infrastructure during migration processes2. The breach's timing, coinciding with the alleged Oracle Cloud compromise, has intensified scrutiny of Oracle's overall security practices and incident response capabilities34.

bleepingcomputer.com favicon
bleepingcomputer.com favicon
acaglobal.com favicon
20 sources
Threat Actor 'rose87168' Actions

The threat actor, known as "rose87168," began selling the allegedly stolen Oracle Cloud data on March 21, 2025, on a dark web forum.12 They claimed to have breached the subdomain login.us2.oraclecloud.com, which was hosting Oracle Fusion Middleware 11G.1 To demonstrate their access, the attacker shared an Archive.org URL containing a text file with their email address, hosted on Oracle's server.3 "rose87168" offered to share data samples with anyone who could help decrypt the stolen credentials and has been actively contacting affected organizations, demanding payment for data removal.41 This aggressive approach has raised concerns about the potential widespread impact of the breach and the security of Oracle's cloud infrastructure.

bleepingcomputer.com favicon
bleepingcomputer.com favicon
acaglobal.com favicon
20 sources
Oracle's Security Concerns

Oracle's recent security incidents have raised significant concerns about the company's overall cybersecurity posture and incident response capabilities. The alleged breaches of Oracle Cloud and Oracle Health have exposed vulnerabilities in both modern cloud infrastructure and legacy systems, highlighting the challenges of maintaining robust security across diverse technological environments.

  • Oracle's use of outdated software, such as Oracle Fusion Middleware 11G on the compromised login.us2.oraclecloud.com subdomain, suggests potential lapses in patch management and system updates12.

  • The company's initial denial of the Oracle Cloud breach, despite evidence provided by multiple customers and security researchers, has drawn criticism and raised questions about transparency in incident reporting34.

  • The exploitation of CVE-2021-35587, a vulnerability reported in December 2022, indicates delays in addressing known security flaws in critical systems42.

  • Oracle's handling of the health data breach, leaving affected healthcare providers to determine HIPAA violations and patient notifications, has been viewed as shifting responsibility onto customers5.

These incidents underscore the need for Oracle to reevaluate and strengthen its security practices, particularly in vulnerability management, system updates, and incident response protocols.

bleepingcomputer.com favicon
bleepingcomputer.com favicon
acaglobal.com favicon
20 sources
Related
How many organizations were affected by the breach
What type of data was stolen from Oracle Cloud
How did Oracle respond to the initial claims of the breach
What steps can organizations take to protect themselves from similar breaches
How effective are Oracle's current security protocols
Keep Reading
Internet Archive Data Breach
Internet Archive Data Breach
According to reports from BleepingComputer, the Internet Archive's "Wayback Machine" has suffered a significant data breach, with hackers compromising the website and stealing a user authentication database containing 31 million unique records.
29,408
Hertz Data Breach Exposes Customers
Hertz Data Breach Exposes Customers
Based on reports from TechCrunch, Hertz, the car rental giant, has confirmed a significant data breach that exposed customers' personal information, including driver's licenses, stemming from a cyberattack on its third-party vendor, Cleo Communications US, LLC.
1,365
The Big National Data Breach
The Big National Data Breach
The National Public Data breach, one of the largest in history, has exposed the personal information of approximately 2.9 billion individuals, raising serious concerns about data security and privacy. As reported by Bloomberg, the breach involved a massive database containing sensitive data such as Social Security numbers, names, and addresses, which was allegedly stolen by cybercriminals and offered for sale on the dark web.
65,853
Blue Shield of California data leak affects 4.7 million people
Blue Shield of California data leak affects 4.7 million people
Blue Shield of California has disclosed a significant data breach affecting 4.7 million members, where protected health information was inadvertently shared with Google's advertising platforms due to a Google Analytics misconfiguration that persisted from April 2021 to January 2024.
2,376