Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
June 6, 2025
No Result
View All Result
Concur News

Home » CISA Highlights Risks of Data Breaches Following Oracle Cloud Hack

CISA Highlights Risks of Data Breaches Following Oracle Cloud Hack

April 21, 2025
in America, Privacy
Reading Time: 3 mins read
CISA Highlights Risks of Data Breaches Following Oracle Cloud Hack

CISA Highlights Risks of Data Breaches Following Oracle Cloud Hack

Share on LinkedinShare on Whatsapp

CISA officials have issued a warning about a data breach affecting Oracle, cautioning about the potential risks to organizations and individuals. The breach was first discovered in January, when hackers stole information and accessed client credentials stored on legacy Oracle systems.

Oracle’s Silence on the Issue

For weeks, Oracle privately informed its customers about the incident, but it avoided making a public announcement. In a letter to customers, Oracle confirmed that Oracle Cloud Infrastructure (OCI) was not breached. However, the company admitted that hackers accessed and published usernames from two outdated servers that were never part of OCI. The FBI and CrowdStrike are currently investigating the incident, according to the letter Oracle sent to customers.

The breach only came to public attention when the hacker, known as “rose87168”, took to social media to brag about the theft. The hacker even offered the stolen documents for sale on cybercriminal forums.

Consent Foundation

Extent of the Breach

Cybersecurity firms, including CloudSEK and CybelAngel, confirmed that the hacker was selling 6 million stolen records. The compromised data came from Oracle Cloud’s Single Sign-On (SSO) and Lightweight Directory Access Protocol (LDAP) systems. More than 140,000 Oracle customers across various industries and regions were impacted by the breach.

Experts discovered that the stolen data included encrypted passwords, key files, and other sensitive information. The hacker, according to CloudSEK, even tried to get help from other hackers to decrypt the stolen credentials. The hacker also threatened Oracle customers, offering to delete their stolen data for a fee.

CISA Issues a Warning

On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) issued a statement saying that, while the full scope of the breach is still unknown, the incident poses significant risks to organizations. CISA highlighted the potential danger of exposed credentials that may be used across different, unaffiliated systems or embedded in various places. CISA explained,

“When credential material is embedded, it is difficult to discover and can enable long-term unauthorized access if exposed.”

The agency also warned that the compromise of credentials, usernames, emails, passwords, authentication tokens, and encryption keys can lead to serious risks, including:

  • Escalating privileges within networks
  • Access to cloud and identity management systems
  • Phishing and business email compromise campaigns
  • Reselling access to stolen credentials
  • Enriching previously stolen data for further intrusions

What Should Organizations Do?

CISA urged organizations to take immediate action to mitigate the risks from the breach:

  • Reset all passwords for affected services
  • Review source code for vulnerabilities
  • Monitor authentication logs for any unusual activity
  • Report any incidents to authorities

Oracle has yet to respond to requests for comment regarding the warning issued by CISA. However, three Oracle Cloud customers have confirmed that their data was included in the leaked set, confirming the severity of the breach.

Also Read: ChatGPT Referring to Users by Name Triggers Privacy Concerns

Tags: Data breachData ProtectionHack

Related Posts

Vodafone
Germany

Vodafone Fined $51 Million by Germany Over Data Privacy Breaches

June 5, 2025
ketan
Interview

Interview with Ketan Modh, Author of Privacy Matters, Sharing Insights on Data Privacy and DPDPA

June 3, 2025
Victoria Secret
News

Victoria’s Secret Website Offline Following Security Breach

May 31, 2025
Aviral
Interview

Interview with Aviral Kulshrestha, Sharing Insights on Navigating GDPR and DPDPA Challenges

May 30, 2025

RECOMMENDED NEWS

dior

Dior Confirms Data Breach, Advises Chinese Customers on Security

3 weeks ago
Ubisoft, Assassin’s Creed Maker, Accused of Collecting Data Without Consent

Ubisoft, Assassin’s Creed Maker, Accused of Collecting Data Without Consent

1 month ago
Aditi

Interview with Aditi Sharma, Senior Consultant (Data Privacy) – Cyber & IT Risk at Grant Thornton

3 weeks ago
Microsoft and Kyndryl Team Up to Strengthen Data Security and Risk Management for Businesses

Microsoft and Kyndryl Team Up to Strengthen Data Security and Risk Management for Businesses

1 month ago

BROWSE BY TOPICS

AI AI Governance AI Privacy Children privacy Compliance Consent Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy Data Protection Data Safeguard Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines Gaurav Mehta GDPR Generative AI google Hack Hacked Industry Interview Investigation Law Meity online services penalty Personal data Press Release Privacy RTI Act Startek Tech giants Technology Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager