Alleged Oracle Cloud Supply Chain Attack
ID: de1eb827-5c36-5441-9abe-d1ba139465c3
STIX ID: report--de1eb827-5c36-5441-9abe-d1ba139465c3
Feed Name: Arctic Wolf Blog
On March 20, 2025 a Breach Forums user claimed to have stolen six million records from Oracle Cloud SSO/LDAP services and offered the data for sale, alleging compromise of login.(region).oraclecloud.com and listing 140,000 impacted organizations; Oracle denies the breach but CloudSEK reported a compromised production SSO endpoint possibly leveraged via a known Oracle Fusion Middleware vulnerability (CVE-2021-35587). Organizations listed are advised to reset/rotate Oracle SSO and LDAP credentials, enforce MFA, and update authentication methods while the incident remains under investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
