Sunday, 8 Feb 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Cloud Computing > Oracle denies breach as hacker offers 6 million records for sale
Cloud Computing

Oracle denies breach as hacker offers 6 million records for sale

Last updated: March 27, 2025 8:53 am
Published March 27, 2025
Share
An open padlock.
SHARE

A reported cyberattack focusing on Oracle Cloud has raised considerations about potential knowledge publicity throughout a variety of organisations.

On March 21, cybersecurity agency CloudSEK stated that 6 million information had been compromised, with over 140,000 Oracle Cloud tenants probably affected.

CloudSEK attributed the incident to a menace actor recognized as “rose87168,” who allegedly obtained the information by means of Oracle’s Single Signal-On (SSO) and Light-weight Listing Entry Protocol (LDAP) programs. The attacker has listed the information on the market on-line and is reportedly demanding cost from affected corporations for knowledge elimination.

Alleged scope and methodology of assault

In keeping with CloudSEK’s findings, the attacker used an undisclosed vulnerability in Oracle WebLogic Server to achieve entry to login endpoints throughout areas related to Oracle Cloud. The uncovered knowledge is alleged to incorporate Java KeyStore (JKS) recordsdata, encrypted passwords for SSO and LDAP programs, key recordsdata, and Enterprise Supervisor JPS keys.

The compromised endpoint is believed to be “login.(region-name).oraclecloud.com.” The attacker has additionally created a profile on X (previously Twitter), showing to observe accounts related to Oracle and affected companies, probably in an effort to stress victims.

CloudSEK has rated the menace as “Excessive” attributable to its reported scale and the sensitivity of the information concerned.

CloudSEK’s response and suggestions

The cybersecurity agency has advisable that organisations utilizing Oracle Cloud take fast actions, equivalent to resetting credentials, launching forensic investigations, monitoring for leaked knowledge on the darkish internet, and making use of stricter entry controls.

CloudSEK additional warned that if the encrypted credentials are efficiently deciphered, there might be far-reaching penalties, like unauthorised entry, potential knowledge leaks, and dangers to linked programs throughout provide chains.

See also  DE-CIX offers new PoP at SINES DC, Portugal

Oracle disputes claims of breach

Oracle has denied that its cloud programs had been compromised. In an announcement to The Register, an organization spokesperson stated, “There was no breach of Oracle Cloud. The revealed credentials will not be for the Oracle Cloud. No Oracle Cloud clients skilled a breach or misplaced any knowledge.”

The corporate’s response adopted on-line exercise by the menace actor, who posted samples of what was claimed to be stolen Oracle Cloud knowledge on cybercrime boards, together with screenshots and a textual content file uploaded to one in every of Oracle’s login servers. The file contained an e mail handle related to the vendor and was captured by the Web Archive’s Wayback Machine.

Whereas Oracle has not commented additional, investigations by third events, together with Bleeping Computer, famous that one of many affected servers was reportedly operating an older model of Oracle Fusion Middleware as lately as February 2025. Safety researchers have speculated that an unpatched essential vulnerability—CVE-2021-35587—might have been concerned, though this has not been confirmed.

Ongoing uncertainty round claims

The attacker, who seems to haven’t any recognized historical past previous to this incident, has additionally supplied the alleged knowledge in change for zero-day exploits or cryptocurrency. In discussion board posts, they claimed to have contacted Oracle a few month earlier with a request for over $200 million in cryptocurrency in return for particulars of the breach.

Additionally they sought help in decrypting the SSO and LDAP credentials, suggesting that the data, whereas encrypted, could be usable with the appropriate instruments or collaboration.

See also  Edge enclosure offers space in tight areas

Along with the information, the attacker shared a listing of domains linked with the affected corporations. They reportedly supplied to take away worker data from particular organisations in change for cost.

What’s recognized and what’s not

At this stage, the total scope and authenticity of the information publicity stay below scrutiny. Oracle maintains that its programs weren’t breached, whereas CloudSEK continues to warn of great dangers tied to the information being circulated. Whether or not this incident displays a verified intrusion or an overstated declare remains to be being evaluated by the broader cybersecurity neighborhood.

See additionally: Oracle’s $5bn UK cloud funding

Need to be taught extra about cybersecurity and the cloud from business leaders? Take a look at Cyber Security & Cloud Expo happening in Amsterdam, California, and London.

Discover different upcoming enterprise know-how occasions and webinars powered by TechForge here.

Source link

TAGGED: breach, denies, hacker, million, offers, Oracle, records, Sale
Share This Article
Twitter Email Copy Link Print
Previous Article Meta Earth to Host Official Launch Event at Token2049 Dubai, Showcasing Modular Blockchain Advancements Meta Earth to Host Official Launch Event at Token2049 Dubai, Showcasing Modular Blockchain Advancements
Next Article Artificial nerve with organic transistor design shows promise for brain-machine interfaces Artificial nerve with organic transistor design shows promise for brain-machine interfaces
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Gcore Korea opens first H100-based data center in Korea

Gcore, the worldwide edge AI, cloud, community, and safety options supplier, held a press convention…

April 10, 2024

Raxio Group achieves Uptime Institute Tier III Certification for data centre in DRC

The Tier III certification course of concerned a rigorous four-day, on-site analysis performed by Uptime…

February 5, 2025

Flex Acquires Crown for $325M to Boost Data Center Power Solutions

Flex (NASDAQ: FLEX) has introduced a definitive settlement to amass Crown Technical Programs for $325…

October 19, 2024

EU introduces draft regulatory guidance for AI models

The release of the “First Draft Basic-Function AI Code of Apply” marks the EU’s effort…

November 15, 2024

Essential Collaboration & Communication Investments for Global Teams

In immediately’s fast-paced international market, working throughout time zones and cultures is just the brand…

November 8, 2024

You Might Also Like

SpaceX
Global Market

Musk’s million data centers in space won’t fly, say experts

By saad
Alphabet boosts cloud investment to meet rising AI demand
Cloud Computing

Alphabet boosts cloud investment to meet rising AI demand

By saad
On how to get a secure GenAI rollout right
Cloud Computing

On how to get a secure GenAI rollout right

By saad
Snowflake and OpenAI push AI into everyday cloud data work
Cloud Computing

Snowflake and OpenAI push AI into everyday cloud data work

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.