Part 2: Validating the Breach Oracle Cloud Denied – CloudSEK’s Follow-Up Analysis
ID: 093714b8-8162-5ecf-86aa-f61e4e3dff59
STIX ID: report--093714b8-8162-5ecf-86aa-f61e4e3dff59
Feed Name: CloudSEK Blog
On 21 March 2025 CloudSEK published evidence that a threat actor ('rose87168') posted data allegedly exfiltrated from an Oracle Cloud SSO endpoint (login.us2.oraclecloud.com), claiming up to 6 million records and widespread tenant impact; CloudSEK verified artifacts (archived file, GitHub references, tenant matches) and released analysis and remediation guidance while Oracle denied a breach, and the actor later released a 10,000-line sample implicating 1,500+ organizations and raising supply-chain and credential compromise risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
