Oracle Denies Claim of Oracle Cloud Breach of 6M Records
ID: 4d0c72be-59eb-5595-afc0-15b672bcb6bc
STIX ID: report--4d0c72be-59eb-5595-afc0-15b672bcb6bc
Feed Name: Dark Reading
Date Published: 2025-03-24
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers at CloudSEK allege a threat actor (rose87168) breached Oracle Cloud SSO/LDAP — possibly via a WebLogic/Oracle Access Manager vulnerability or an as-yet-unreleased zero-day — exfiltrating 6 million records (including JKS, encrypted SSO passwords, key files) which are being offered for sale and used for extortion; Oracle denies any breach, and CloudSEK published corroborating evidence and a tool for customers to check exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
