Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
May 13, 2025
No Result
View All Result
Concur News

Home » CISA Highlights Risks of Data Breaches Following Oracle Cloud Hack

CISA Highlights Risks of Data Breaches Following Oracle Cloud Hack

April 21, 2025
in America, Privacy
Reading Time: 3 mins read
CISA Highlights Risks of Data Breaches Following Oracle Cloud Hack

CISA Highlights Risks of Data Breaches Following Oracle Cloud Hack

Share on LinkedinShare on Whatsapp

CISA officials have issued a warning about a data breach affecting Oracle, cautioning about the potential risks to organizations and individuals. The breach was first discovered in January, when hackers stole information and accessed client credentials stored on legacy Oracle systems.

Oracle’s Silence on the Issue

For weeks, Oracle privately informed its customers about the incident, but it avoided making a public announcement. In a letter to customers, Oracle confirmed that Oracle Cloud Infrastructure (OCI) was not breached. However, the company admitted that hackers accessed and published usernames from two outdated servers that were never part of OCI. The FBI and CrowdStrike are currently investigating the incident, according to the letter Oracle sent to customers.

The breach only came to public attention when the hacker, known as “rose87168”, took to social media to brag about the theft. The hacker even offered the stolen documents for sale on cybercriminal forums.

Consent Foundation

Extent of the Breach

Cybersecurity firms, including CloudSEK and CybelAngel, confirmed that the hacker was selling 6 million stolen records. The compromised data came from Oracle Cloud’s Single Sign-On (SSO) and Lightweight Directory Access Protocol (LDAP) systems. More than 140,000 Oracle customers across various industries and regions were impacted by the breach.

Experts discovered that the stolen data included encrypted passwords, key files, and other sensitive information. The hacker, according to CloudSEK, even tried to get help from other hackers to decrypt the stolen credentials. The hacker also threatened Oracle customers, offering to delete their stolen data for a fee.

CISA Issues a Warning

On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) issued a statement saying that, while the full scope of the breach is still unknown, the incident poses significant risks to organizations. CISA highlighted the potential danger of exposed credentials that may be used across different, unaffiliated systems or embedded in various places. CISA explained,

“When credential material is embedded, it is difficult to discover and can enable long-term unauthorized access if exposed.”

The agency also warned that the compromise of credentials, usernames, emails, passwords, authentication tokens, and encryption keys can lead to serious risks, including:

  • Escalating privileges within networks
  • Access to cloud and identity management systems
  • Phishing and business email compromise campaigns
  • Reselling access to stolen credentials
  • Enriching previously stolen data for further intrusions

What Should Organizations Do?

CISA urged organizations to take immediate action to mitigate the risks from the breach:

  • Reset all passwords for affected services
  • Review source code for vulnerabilities
  • Monitor authentication logs for any unusual activity
  • Report any incidents to authorities

Oracle has yet to respond to requests for comment regarding the warning issued by CISA. However, three Oracle Cloud customers have confirmed that their data was included in the leaked set, confirming the severity of the breach.

Also Read: ChatGPT Referring to Users by Name Triggers Privacy Concerns

Tags: Data breachData ProtectionHack

Related Posts

Texas
America

Google will pay Texas $1.4 billion to settle claims the company collected users’ data without permission

May 12, 2025
Michigan
LAW

Michigan Attorney General Sues Roku for Alleged COPPA Violations

May 10, 2025
EIB
Europe

EDPS Blocks EIB’s Data Transfer to India Over Privacy Law Concerns

May 10, 2025
Pearson
Europe

Pearson Confirms Cyberattack, Customer Data and Source Code Stolen

May 10, 2025

RECOMMENDED NEWS

Pearson

Pearson Confirms Cyberattack, Customer Data and Source Code Stolen

3 days ago
Landmark Admin

Landmark Admin Data Breach Now Affects 1.6 Million Poeple

3 weeks ago
privacy feature

WhatsApp Testing New Privacy Feature : Control Media Saving

1 month ago

Data Privacy in Sweden: Court Battle Over Selling Personal Data

1 month ago

BROWSE BY TOPICS

AI AI Governance AI Privacy Children privacy Compliance Consent Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy Data Protection Data Safeguard Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines Fraud GDPR Generative AI Hack Hacked Industry Interview Investigation Law penalty Personal data PHI PII Press Release Privacy RBI RTI Act Startek Tech giants Technology Training Trending

Trimtab Innovation Pvt. Ltd 701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
error: Content is protected !!
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager