Alleged Oracle Cloud Supply Chain Attack: Six Million Records Stolen, 140K Companies Affected
ID: 0b95439c-3661-5efb-941d-c550fc2a2eae
STIX ID: report--0b95439c-3661-5efb-941d-c550fc2a2eae
Feed Name: Arctic Wolf
A Breach Forums user claimed on March 20, 2025 that six million records were stolen from Oracle Cloud SSO/LDAP endpoints and offered the data for sale, listing ~140,000 impacted organizations and artifacts (encrypted SSO/LDAP passwords, JKS files, keys); Oracle has publicly denied any customer data loss, while CloudSEK's analysis suggests a production SSO endpoint (login.us2.oraclecloud.com) may have been compromised potentially via a known Oracle Fusion Middleware vulnerability (CVE-2021-35587); recommended actions include resetting/rotating Oracle SSO and LDAP credentials, enforcing MFA, and updating authentication methods.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
