• News/
  • https://www.bleepingcomputer.com/news/security/oracle-privately-confirms-cloud-breach-to-customers/

Oracle privately confirms Cloud breach to customers

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 3, 2025
·
Updated

Oracle has finally acknowledged to some customers that attackers have stolen old client credentials after breaching a "legacy environment" last used in 2017, Bloomberg reported. However, while Oracle told clients this is old legacy data that is not sensitive, the threat actor behind the attack has shared data with BleepingComputer from the end of 2024 and posted newer records from 2025 on a hacking forum. According to Bloomberg, the company also informed clients that cybersecurity firm CrowdStrike and the FBI are investigating the incident. Cybersecurity firm CybelAngel first revealed that Oracle told clients that an attacker who gained access to the company's Gen 1 (also known as Oracle Cloud Classic) servers as early as January 2025 used a 2020 Java exploit to deploy a web shell and additional malware. During the breach, detected in late February, the attacker allegedly exfiltrated data from the Oracle Identity Manager (IDM) database, including user emails, hashed passwords, and usernames. This comes after a threat actor (known as rose87168) put up for sale 6 million data records on BreachForums on March 20 and released multiple text files containing a sample database, LDAP information, and a list of the companies as proof that the data was legitimate, all of them allegedly stolen from Oracle Cloud's federated SSO login servers. ​When asked to confirm the authenticity of the leaked data, Oracle told BleepingComputer that "There has been no breach of Oracle Cloud. The publi...

Read full article

Affected Software

8 affected components
Oracle Gen 1
Oracle Oracle Cloud Classic
Oracle Oracle Cloud
Oracle Oracle Identity Manager
Oracle Oracle Health
Oracle Cerner
Oracle Cloud Classic
Oracle Identity Manager
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Oracle's confirmation of a security breach involving the theft of old client credentials from a legacy environment.

2

What security implications are discussed in the article?

The article highlights concerns regarding the exposure of obsolete user credentials and potential risks to customers' data security.

3

What products or software are affected by this breach?

The affected products include Oracle Gen 1, Oracle Cloud Classic, Oracle Cloud, Oracle Identity Manager, Oracle Health, and Cerner.

4

When was the last use of the breached legacy environment noted by Oracle?

The legacy environment was last used in 2017 before the breach occurred.

5

How did Oracle communicate the breach to its customers?

Oracle privately informed its customers about the breach involving outdated client credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203