logo

Part 2: Validating the Breach Oracle Cloud Denied – CloudSEK’s Follow-Up Analysis

ID: 093714b8-8162-5ecf-86aa-f61e4e3dff59

STIX ID: report--093714b8-8162-5ecf-86aa-f61e4e3dff59

Feed Name: CloudSEK Blog

Threat Score
80/100

Date Published: 2025-03-24

Date Updated: 2026-04-27

...
...

On 21 March 2025 CloudSEK published evidence that a threat actor ('rose87168') posted data allegedly exfiltrated from an Oracle Cloud SSO endpoint (login.us2.oraclecloud.com), claiming up to 6 million records and widespread tenant impact; CloudSEK verified artifacts (archived file, GitHub references, tenant matches) and released analysis and remediation guidance while Oracle denied a breach, and the actor later released a 10,000-line sample implicating 1,500+ organizations and raising supply-chain and credential compromise risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.