• News/
  • https://www.theregister.com/2025/04/08/oracle_cloud_compromised/

Oracle tells customers its public cloud was compromised

The Register
·
Iain Thomson
·
Published Apr 8, 2025
·
Updated

Oracle has briefed some customers about a successful intrusion into its public cloud, as well as the theft of their data, after previously denying it had been compromised. Claims of a cyberattack on Oracle’s cloud service emerged in late March when a miscreant using the handle “rose87168” boasted of cracking into two of Big Red's login servers for customers and harvesting around six million records, which included clients’ private security keys, encrypted credentials, and LDAP entries. The netizen put the info, involving thousands of organizations, up for sale on a cybercrime forum. The Safra Catz-run database giant swore blind the claims were false. It turns out the only thing false were the denials. Multiple information security experts analyzed samples of the stolen data, shared by rose87168 as proof of their heist, and concluded Oracle's Cloud Classic product was indeed compromised by the thief, likely by exploiting Oracle-hosted login servers that weren't patched against CVE-2021-35587, a vulnerability in Oracle Access Manager, a product in the Oracle Fusion Middleware suite. Oracle hadn't patched a hole in its own software on its own systems, leading to the theft of info. No wonder it kept quiet. The data thief even created a text file in early March on login.us2.oraclecloud.com containing their email address to show they had access at one point. Now, two of the IT titan's customers have said Oracle contacted them to quietly discuss the theft of their data from its clou...

Read full article

Affected Software

3 affected components
Oracle Oracle Cloud Classic
Oracle Oracle Fusion Middleware
Oracle Cloud Classic
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a successful intrusion into Oracle's public cloud and the subsequent data theft.

2

What security implications are discussed?

The intrusion raises concerns about data security and potential vulnerabilities within Oracle's cloud infrastructure.

3

What products or software are affected?

The affected products include Oracle Cloud Classic and Oracle Fusion Middleware.

4

What did Oracle initially deny before confirming the breach?

Oracle initially denied that its public cloud had been compromised before later briefing customers about the breach.

5

How did Oracle inform its customers about the breach?

Oracle briefed some customers directly regarding the successful intrusion and data theft.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203