logo

Oracle Cloud says it's not true someone broke into its login servers and stole data

ID: 323c4dce-f984-5e3b-9fc7-26781ac9e0ea

STIX ID: report--323c4dce-f984-5e3b-9fc7-26781ac9e0ea

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2025-03-23

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A threat actor claims to have stolen about six million Oracle Cloud-related records (including Java KeyStore files, encrypted SSO and LDAP credentials, and other sensitive artifacts) by exploiting an Oracle Fusion Middleware vulnerability (CVE-2021-35587) and is attempting to sell the data; Oracle publicly denies any breach, but archived samples and seller posts were shared as proof, leaving the incident unconfirmed yet potentially wide-reaching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.