Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
May 31, 2025
No Result
View All Result
Concur News

Home » Oracle Privately Notifies Customers of Cloud Security Breach

Oracle Privately Notifies Customers of Cloud Security Breach

April 7, 2025
in News, Privacy
Reading Time: 3 mins read
Oracle Privately Notifies Customers of Cloud Security Breach
Share on LinkedinShare on Whatsapp

Oracle has privately informed some customers that hackers breached a legacy system unused since 2017. The attackers stole old client credentials. Oracle claimed the data was outdated and not sensitive. However, the hacker shared newer files from late 2024 and 2025 with BleepingComputer and posted them on a hacking forum. Oracle stated that the FBI and cybersecurity firm CrowdStrike are now investigating the Cloud Security incident.

The breach targeted Oracle’s older cloud system, known as Gen 1 or Oracle Cloud Classic. Cybersecurity firm CybelAngel said Oracle notified customers in January 2025. A hacker had accessed the old servers using a Java vulnerability from 2020. The attacker installed a web shell and other malware, raising concerns about legacy system security.

Oracle discovered the breach in late February. During this time, the hacker stole data from Oracle Identity Manager (IDM). This data included user emails, usernames, and hashed passwords.

Consent Foundation

On March 20, a hacker named “rose87168” listed 6 million records for sale on BreachForums. They shared samples with LDAP info, usernames, and company names to prove authenticity. The hacker claimed the data came from Oracle Cloud’s federated login system.

When asked by BleepingComputer, Oracle denied a breach of Oracle Cloud. The company said the leaked credentials were not from its current cloud platform. Oracle also stated that no Oracle Cloud customers lost any data.

Still, archived links showed files with the hacker’s email were uploaded to Oracle’s server. Though Archive.org removed the files, backup copies are still available online.

BleepingComputer later confirmed the leaked samples with several affected companies. The data included names, email addresses, LDAP display names, and other identifiers.

Despite this, Oracle continues to deny a breach of its current cloud services. It says the issue only impacted Oracle Cloud Classic.

Cybersecurity expert Kevin Beaumont explained the name difference. He said Oracle is using this distinction to avoid admitting a breach of “Oracle Cloud.” Experts warn that legacy systems, if left unmaintained, pose serious Cloud Security risks.

Meanwhile, Oracle has not responded to further questions from BleepingComputer regarding the breach.

Oracle Health Also Hit by Cloud Security Breach

In a separate incident, Oracle also told clients about a breach at Oracle Health (formerly known as Cerner), affecting several U.S. hospitals and healthcare providers.

Although Oracle hasn’t publicly announced this incident, BleepingComputer confirmed the theft of patient data, supported by private communications between Oracle Health and the impacted clients.

Oracle Health discovered the breach on February 20, 2025, and identified that it involved older Cerner data migration servers. Hackers reportedly used stolen customer credentials to access the servers after January 22, 2025.

Sources say that a hacker calling himself “Andrew” is now extorting affected hospitals, demanding millions in cryptocurrency to prevent the release of stolen patient data. He has even created websites to pressure these organizations into paying.

Bleeping Computer has reached out to Oracle Health several times since March 4, but has not received a response.

Tags: Data breachPrivacyTech giants

Related Posts

Consent Managers
India

Consent Managers, Not AAs, Will Lead the Way [Opinion]

May 31, 2025
Victoria Secret
News

Victoria’s Secret Website Offline Following Security Breach

May 31, 2025
Aviral
Interview

Interview with Aviral Kulshrestha, Sharing Insights on Navigating GDPR and DPDPA Challenges

May 30, 2025
Vijayashankar Nagarajarao
Interview

Interview with Vijayashankar Nagarajarao (Naavi), Founder of FDPPI, Sharing Insights on Cyber Law, Data Privacy, and DPDPA

May 28, 2025

RECOMMENDED NEWS

Lyft Incident Raises Privacy Concerns After Unsolicited Text of Conversation Transcript

“I was like ‘who is tapping me?” Lyft Passenger Gets Text with Conversation Transcript, Igniting Privacy Worries

1 month ago
Fake Government Email ID Used to Scam Bank of Rs 1.32 Crore

Fake Government Email ID Used to Scam Bank of Rs 1.32 Crore

1 month ago
APAAR ID: Simplifying Education, Raising Privacy Concerns

APAAR ID: Simplifying Education, Raising Privacy Concerns

2 months ago
draft rules

Draft DPDP Rules: Banks Prepare to Tackle Operational Challenges

1 week ago

BROWSE BY TOPICS

AI AI Governance AI Privacy Apps Children privacy Compliance Consent consent managers Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy Data Protection Data Safeguard Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR Generative AI google Hack Hacked Industry Interview Investigation Law penalty Personal data PHI Press Release Privacy RTI Act Startek Tech giants Technology Training Trending

Trimtab Innovation Pvt. Ltd 701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager