logo

Oracle Cloud Users Urged to Take Action

ID: f2d4327f-7760-5c25-a18b-0c5942087140

STIX ID: report--f2d4327f-7760-5c25-a18b-0c5942087140

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-03-31

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Allegations emerged that a threat actor is selling ~6 million records purportedly exfiltrated from Oracle cloud SSO/LDAP—affecting an estimated ~140k tenants—and including encrypted passwords, keystore/key files and admin-account metadata; researchers validated samples, recommended immediate credential and key rotation, session invalidation, MFA enforcement and enhanced monitoring, while Oracle has denied an OCI breach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.