Oracle has finally admitted to some of its customers that attackers have stolen old customer credentials after breaching a “legacy environment” last used in 2017, according to a Bloomberg report.
See also: Do Oracle and Microsoft want to acquire TikTok?

However, while Oracle has informed its customers that this data is old and not sensitive, the perpetrator behind the attack has shared data with BleepingComputer since late 2024 and has posted newer logs from 2025 on a hacking forum.
According to Bloomberg, the company also informed its customers that cybersecurity firm CrowdStrike and the FBI are investigating the incident.
Cybersecurity firm CybelAngel revealed that Oracle has notified its customers about an attacker who gained access to Gen 1 servers (also known as Oracle Cloud Classic) since January 2025, using a 2020 Java exploit to install a web shell and additional malware.
During the breach, which was detected in late February, the attacker allegedly extracted data from the Oracle Identity Manager (IDM) database, including user email addresses, passwords in encrypted form, and names.
This came after a malicious actor (known as rose87168 ) was reported to have sold 6 million data files on BreachForums on March 20th and published multiple text files containing a sample database, LDAP information, and a list of companies as proof that the data was genuine, all allegedly stolen from Oracle Cloud SSO servers .
See also: Oracle: Customers say their data was leaked after breach
When asked to confirm the authenticity of the data leaks, Oracle told BleepingComputer that “There has been no breach of Oracle Cloud. The published credentials do not pertain to Oracle Cloud. No Oracle Cloud customers were breached or lost data.”

Oracle denied this information, despite the fact that an archived URL showed that the perpetrator had uploaded a file containing his email address to one of Oracle's servers. This URL was later removed from Archive.org, but a file of the archive still exists.
However, a few days later, BleepingComputer confirmed with multiple companies that additional samples of the leaks (including relevant LDAP display names, email addresses, names, and other identifying information) obtained from the perpetrator were valid.
Oracle has consistently denied reports of an Oracle Cloud breach in statements it has shared with the press since the incident emerged. This is incontrovertible, as it agrees with reports that Oracle is informing its customers that the breach affects an older platform known as Oracle Cloud Classic.
See also: CISA adds Microsoft and Zimbra vulnerabilities to KEV list
Cloud breach refers to the improper access, leakage, or circumvention of data stored in cloud infrastructures (i.e., on external servers and storage managed by third parties, such as Amazon Web Services, Microsoft Azure, Google Cloud, etc.). To prevent such breaches, organizations must adopt strong security practices, such as encrypting data, using strong passwords and multi-factor authentication (MFA), keeping their systems updated, and monitoring for suspicious activity.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
