• News/
  • https://www.theregister.com/2025/03/23/oracle_cloud_customers_keys_credentials/

Oracle Cloud denies claims of server intrusion

The Register
·
Jessica Lyons
·
Published Mar 23, 2025
·
Updated

Oracle has straight up denied claims by a miscreant that its public cloud offering has been compromised and information stolen. A crook late last week advertised on an online cyber-crime forum what was alleged to be Oracle Cloud customer security keys and other sensitive data swiped from the IT giant. This material was said to have been obtained by the miscreant from at least one of the cloud provider's single-sign-on (SSO) login servers by exploiting a security vulnerability. Oracle says that's not true. "There has been no breach of Oracle Cloud," a spokesperson told The Register on Friday. "The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data." Meanwhile, as noted by the guys at Bleeping, the miscreant boasted of creating a text file on an Oracle Cloud login server, specifically login.us2.oraclecloud.com, captured here by the Internet Archive's Wayback Machine in early March, as proof that systems were compromised. That file contains simply the email address of the person attempting to sell what's said to be the stolen Oracle Cloud data. We've asked Oracle for further clarification or an explanation. It's claimed that information was exfiltrated from the EM2 as well as US2 login server. Samples of allegedly stolen info were also shared by the would-be thief. Looking through the Wayback Machine, we can see that the US2 server was as recently as February 2025 running some form of Oracle Fusion Middleware 11G. ...

Read full article

Affected Software

3 affected components
Oracle Fusion Middleware=11G
Oracle Oracle Access Manager
Oracle Cloud
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Oracle Cloud's denial of claims regarding a server intrusion and the alleged theft of customer security keys.

2

What security implications are discussed in the article?

The article highlights concerns over the potential compromise of customer security credentials and the integrity of Oracle Cloud's security measures.

3

What products or software are affected by the allegations?

The affected products include Oracle Fusion Middleware 11G, Oracle Access Manager, and Oracle Cloud services.

4

What is Oracle's response to the claims of compromise?

Oracle has outright denied the claims of server intrusion and theft of customer information.

5

Who made the claims about the Oracle Cloud breach?

The claims were made by an individual on an online cyber-crime forum, alleging possession of customer security keys.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203