logo

Alleged Oracle Cloud Supply Chain Attack

ID: de1eb827-5c36-5441-9abe-d1ba139465c3

STIX ID: report--de1eb827-5c36-5441-9abe-d1ba139465c3

Feed Name: Arctic Wolf Blog

Threat Score
65/100

Date Published: 2025-03-25

Date Updated: 2026-04-27

...
...

On March 20, 2025 a Breach Forums user claimed to have stolen six million records from Oracle Cloud SSO/LDAP services and offered the data for sale, alleging compromise of login.(region).oraclecloud.com and listing 140,000 impacted organizations; Oracle denies the breach but CloudSEK reported a compromised production SSO endpoint possibly leveraged via a known Oracle Fusion Middleware vulnerability (CVE-2021-35587). Organizations listed are advised to reset/rotate Oracle SSO and LDAP credentials, enforce MFA, and update authentication methods while the incident remains under investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.