logo

The Biggest Supply Chain Hack Of 2025: 6M Records Exfiltrated from Oracle Cloud affecting over 140k Tenants

ID: 13415a6a-35af-5a1a-ba34-81dceb8506fc

STIX ID: report--13415a6a-35af-5a1a-ba34-81dceb8506fc

Feed Name: CloudSEK Blog

Threat Score
80/100

Date Published: 2025-03-21

Date Updated: 2026-04-27

...
...

CloudSEK’s XVigil reports that threat actor 'rose87168' is selling approximately 6 million records exfiltrated from Oracle Cloud SSO and LDAP — including JKS files, encrypted SSO passwords, key files, and enterprise manager JPS keys — and is extorting affected tenants (over 140k) for payment; the actor claims access via a login subdomain and the analysis links the incident to exploitation of an older Oracle Fusion Middleware vulnerability (CVE-2021-35587), prompting recommendations for immediate credential and secret rotation, enhanced monitoring, and coordination with Oracle.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.