logo

Oracle attempt to hide serious cybersecurity incident from customers in Oracle SaaS service

ID: e92f5053-d024-50d8-8ce4-ba344db27637

STIX ID: report--e92f5053-d024-50d8-8ce4-ba344db27637

Feed Name: DoublePulsar

Threat Score
85/100

Date Published: 2025-03-31

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

A threat actor (rose87168) claims to have breached Oracle systems and released proof including an archive link, multi-hour internal meeting recordings demonstrating access to password vaults and customer-facing systems, and current Oracle configuration files; journalists and some customers validated that customer data (e.g., staff email addresses) appeared in the released material while Oracle publicly denied a cloud breach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.