Oracle quietly confirms public cloud data breach, customer data stolen

 Oracle quietly confirms public cloud data breach, customer data stolen

Published on April 8, 2025 | Category: tech

Oracle quietly confirms public cloud data breach, customer data stolen

News
By Sead Fadilpašić published

The company is sending out breach notifications

Oracle
(Image credit: Oracle)

  • The data breach that Oracle first denied has now been confirmed
  • The company is reaching out to affected customers
  • Oracle is facing an alleged lawsuit

Oracle has started notifying customers about the recent data breach at its cloud services.

In early April, a threat actor with the alias “rose87168” opened a new thread on an underground forum to advertise the sale of a database stolen from the company. The database allegedly contained six million records, including private security keys, encrypted credentials, and LDAP entries, all belonging to Oracle customers.

To confirm the authenticity of the information, the hacker even uploaded a new document to the cloud, containing their own email address.

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

View Deal

Lawsuit incoming?

At first, Oracle denied the claims, but later confirmed them. However, it also tried to downplay the importance of the hack, claiming the data was taken from an old, unused server, and that the information found there was eight years old and thus obsolete. However, there might be more to this story.

According to The Register, the data belonging to one of the victims was created in 2024. Another victim (we’re not sure if it’s the same company, or a different one) is preparing to sue Oracle over the incident. The Register also notes that Oracle has reached out to at least two organizations so far.

The investigation is currently ongoing and the details won’t be known until it’s concluded. So far, it seems that the attacker exploited a vulnerability in Oracle Access Manager to breach Oracle-hosted servers. The vulnerability is tracked as CVE-2021-35587, and was assigned a critical severity score 9.8/10. It was patched in mid-January, 2022, raising questions over whether Oracle kept its own servers vulnerable to a flaw it fixed more than three years ago.

Cybersecurity experts CrowdStrike are currently analyzing the incident. The FBI was also notified about the attack, Oracle has confirmed.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

Via The Register

You might also like

  • Oracle admits second major security breach, user login data stolen
  • We've rounded up the best password managers
  • Take a look at our guide to the best authenticator app
Sead Fadilpašić

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

More about security
Ransomware

Port of Seattle ransomware breach exposes data on around 90,000 people

Laptop screen with red background and a warning sign in the middle

Still using WinRAR? It has a worrying security flaw that could let hackers hijack your Windows device

Latest
Google Gemini AI

We've tried Google Pixel 9's new Gemini Astra upgrade, and users are in for a real treat

See more latest
Most Popular
Google Gemini AI
We've tried Google Pixel 9's new Gemini Astra upgrade, and users are in for a real treat
Samsung Galaxy S24 Ultra home screen with clock and weather
You might be waiting until June to get One UI 7 on your Samsung Galaxy device
Denon AH-C840NCW true wireless earbuds in white, in their charging case on a green fabric and wooden surface
Denon's AirPods-like new earbuds range beats Apple with next-gen Bluetooth audio and a tempting low price
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
The Samsung Galaxy S25 Edge could be the second-priciest S25 model, if this leak is accurate
iPhone 15
iPhone panic-buying hits Apple Stores, but tariff impacts may not be as bad as feared
Nintendo Switch 2 live coverage.
The news that the Nintendo Switch 2 Joy-Con don't have Hall effect thumbsticks has left me wondering what the point was
Audio-Technica ATH-R30x headphones
Audio-Technica's new cheap headphones look like the audio bargain of the century
Nintendo Switch 2 Welcome Tour
Nintendo of America president Doug Bowser seemingly reveals the Nintendo Switch 2 Welcome Tour price
Robin image created using ChatGPT
ChatGPT free users, look away now! OpenAI is testing watermarks on image generation that could render the feature redundant unless you pay
Apple iPhone 16 Pro REVIEW
Sketchy iOS 19 leak suggests your iPhone could soon look a lot more like Android

Related Articles

Spotify is about to be flooded with AI-made ads, and I wonder if it will make much of a difference to businesses

Spotify’s new AI-powered ad tool may not be the solution they claim....

Read More
CinemaCon 2025 live – first Avatar 3 reaction, juicy Fantastic Four news,

CinemaCon 2025 is officially underway – here are all new movie announc...

Read More
NYT Wordle today — answer and my hints for game #1385, Friday, April 4

Looking for Wordle hints? I can help. Plus get the answers to Wordle t...

Read More