Oracle says “obsolete servers” hacked, denies cloud breach


- Oracle had started sending out data breach notification letters
- In the letters, it downplays the significance of recent attacks
- However not everyone agrees with that assessment
We now apparently have confirmation that Oracle has been notifying its customers about a recent data breach – but the company is still standing its ground and saying it was an irrelevant attack that will make no difference whatsoever.
In early April 2025, a threat actor with the alias “rose87168” opened a new thread on an underground forum to advertise the sale of a database stolen from the company. The database allegedly contained six million records, including private security keys, encrypted credentials, and LDAP entries, all belonging to Oracle customers.
To confirm the authenticity of the information, the hacker even uploaded a new document to the cloud, containing their own email address.
Oracle denies severity
Oracle first denied, and later confirmed the breach, but said it was a pointless attack since the servers were old and unused, and the data contained within was outdated.
Now, BleepingComputer reports that email notification letters started going out: “Oracle would like to state unequivocally that the Oracle Cloud—also known as Oracle Cloud Infrastructure or OCI—has NOT experienced a security breach,” the letter allegedly reads.
“No OCI customer environment has been penetrated. No OCI customer data has been viewed or stolen. No OCI service has been interrupted or compromised in any way,” it added in emails sent from [email protected], prompting customers to contact Oracle Support or their account manager if they have additional questions.
“A hacker did access and publish user names from two obsolete servers that were never a part of OCI. The hacker did not expose usable passwords because the passwords on those two servers were either encrypted and/or hashed. Therefore the hacker was not able to access any customer environments or customer data.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
A report from The Register claims the data belonging to one of the victims was created in 2024. The investigation is currently ongoing but so far it seems that the attacker exploited a vulnerability in Oracle Access Manager to breach Oracle-hosted servers.
Cybersecurity experts CrowdStrike are currently analyzing the incident. The FBI was also notified about the attack, Oracle has confirmed.
Via BleepingComputer
You might also like
Oracle had started sending out data breach notification letters In the letters, it downplays the significance of recent attacks However not everyone agrees with that assessment We now apparently have confirmation that Oracle has been notifying its customers about a recent data breach – but the company is still standing…
Recent Posts
- 191 Prime Day Deals Picked By People Who Obsessively Test Gear
- US arrests Silk Typhoon hacker accused of stealing Covid research and mass email hacking
- The best Prime Day deals on our favorite robot vacuums
- I used to work at the Apple Store – and the rumored AI-powered Support app sounds genius
- The 198 Prime Day 2025 deals you can still get
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022