Oracle has finally acknowledged to some customers that attackers have stolen old client credentials after breaching a "legacy environment" last used in 2017, Bloomberg reported. However, while Oracle told clients this is old legacy data that is not sensitive, the threat actor behind the attack has shared data with BleepingComputer from the end of 2024 and posted newer records from 2025 on a hacking forum. According to Bloomberg, the company also informed clients that cybersecurity firm CrowdStrike and the FBI are investigating the incident. Cybersecurity firm CybelAngel first revealed that Oracle told clients that an attacker who gained access to the company's Gen 1 (also known as Oracle Cloud Classic) servers as early as January 2025 used a 2020 Java exploit to deploy a web shell and additional malware. During the breach, detected in late February, the attacker allegedly exfiltrated data from the Oracle Identity Manager (IDM) database, including user emails, hashed passwords, and usernames. This comes after a threat actor (known as rose87168) put up for sale 6 million data records on BreachForums on March 20 and released multiple text files containing a sample database, LDAP information, and a list of the companies as proof that the data was legitimate, all of them allegedly stolen from Oracle Cloud's federated SSO login servers. When asked to confirm the authenticity of the leaked data, Oracle told BleepingComputer that "There has been no breach of Oracle Cloud. The publi...
Oracle reportedly confirms Oracle Cloud breach to customers
BleepingComputer
·Sergiu Gatlan
·Published Apr 3, 2025
·Updated
Affected Software
4 affected components
Oracle Gen 1 (Oracle Cloud Classic)
Oracle Health legacy Cerner data migration servers
Oracle Cloud Classic
Oracle Identity Manager
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Oracle's confirmation of a data breach involving old client credentials from a legacy environment.
2
What security implications are discussed in the article?
The breach potentially exposes sensitive data due to the theft of outdated client credentials.
3
What specific products or software are affected by the breach?
The breach affects Oracle Gen 1 (Oracle Cloud Classic), Oracle Health legacy Cerner data migration servers, and Oracle Identity Manager.
4
When was the legacy environment last in use?
The legacy environment that was breached was last used in 2017.
5
How did Oracle communicate the breach to its customers?
Oracle reportedly informed some customers about the breach through direct communication.