The Biggest Supply Chain Hack Of 2025: 6M Records Exfiltrated from Oracle Cloud affecting over 140k Tenants
ID: 13415a6a-35af-5a1a-ba34-81dceb8506fc
STIX ID: report--13415a6a-35af-5a1a-ba34-81dceb8506fc
Feed Name: CloudSEK Blog
CloudSEK’s XVigil reports that threat actor 'rose87168' is selling approximately 6 million records exfiltrated from Oracle Cloud SSO and LDAP — including JKS files, encrypted SSO passwords, key files, and enterprise manager JPS keys — and is extorting affected tenants (over 140k) for payment; the actor claims access via a login subdomain and the analysis links the incident to exploitation of an older Oracle Fusion Middleware vulnerability (CVE-2021-35587), prompting recommendations for immediate credential and secret rotation, enhanced monitoring, and coordination with Oracle.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
