logo

Oracle customers confirm data stolen in alleged cloud breach is valid

ID: cbc256a9-c5f0-5935-b9e5-614f07d575a1

STIX ID: report--cbc256a9-c5f0-5935-b9e5-614f07d575a1

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-03-26

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Allegations that a threat actor 'rose87168' breached Oracle Cloud federated SSO servers and is selling purported authentication data and encrypted passwords for approximately 6 million users; affected companies provided sample validation and archive evidence shows a file on login.us2.oraclecloud.com and a server running Oracle Fusion Middleware 11g (CVE-2021-35587), although Oracle denies any breach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.