logo

Oracle Denies Claim of Oracle Cloud Breach of 6M Records

ID: 4d0c72be-59eb-5595-afc0-15b672bcb6bc

STIX ID: report--4d0c72be-59eb-5595-afc0-15b672bcb6bc

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-03-24

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers at CloudSEK allege a threat actor (rose87168) breached Oracle Cloud SSO/LDAP — possibly via a WebLogic/Oracle Access Manager vulnerability or an as-yet-unreleased zero-day — exfiltrating 6 million records (including JKS, encrypted SSO passwords, key files) which are being offered for sale and used for extortion; Oracle denies any breach, and CloudSEK published corroborating evidence and a tool for customers to check exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.