logo

Oracle Appears to Admit Breach of 2 'Obsolete' Servers

ID: e874e966-2772-5b2e-9cb5-75d7e8285df2

STIX ID: report--e874e966-2772-5b2e-9cb5-75d7e8285df2

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2025-04-09

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Oracle notified some customers of a breach involving two obsolete non-OCI servers after a threat actor ("rose87168") claimed to have exfiltrated about 6 million records from Oracle SSO/LDAP and related key files; Oracle maintains the data on those servers was hashed/encrypted and that no OCI customer environments were breached. Researchers and vendors (CloudSEK, Trustwave) observed attempts to sell the data and raised concerns that usernames and cryptographically protected credentials could still present risk through aggregation, credential stuffing, or potential decryption depending on implementations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.