HomeSecurityOracle says "obsolete servers" have been compromised

Oracle says 'obsolete servers' have been compromised

Oracle eventually confirmed through email notifications sent to its customers that a hacker stole and leaked credentials from what it described as “two outdated servers.”

See also: Oracle confirms Cloud breach to customers

Oracle servers

However, the company clarified that Oracle Cloud servers were not affected and that the incident had no impact on customer data and services.

Since the incident first broke in March, when a malicious actor ( rose87168 ) offered 6 million data files for sale on BreachForums , Oracle has consistently denied reports of an Oracle Cloud breach in press statements. While that is true, as it aligns with what Oracle has been telling its customers—that the breach affects an older platform, Oracle Cloud Classic —it is simply a rhetorical statement, according to cybersecurity expert Kevin Beaumont .

This came after the company privately acknowledged in phone conversations with some of its customers a week ago that attackers stole old customer credentials after breaching a “legacy environment” that had last been used in 2017.

See also: Oracle: Customers say their data was leaked after breach

However, while Oracle informed its customers that this data was old and non-sensitive, the perpetrator behind the breach shared data with BleepingComputer from late 2024 and then posted newer entries from 2025 on BreachForums.

Oracle says "obsolete servers" have been compromised

Cybersecurity firm CybelAngel revealed last week that Oracle had notified its customers about an attack in which an attacker installed a web shell and additional malware on some of its Gen 1 servers (also known as Oracle Cloud Classic) as early as January 2025. By the time the breach was detected in late February, the attacker had allegedly stolen data from the Oracle Identity Manager (IDM) database , including user email addresses, passwords in encrypted form, and usernames.

Last month, BleepingComputer reported that Oracle privately notified its customers of another breach that occurred in January at Oracle Health (a software-as-a-service (SaaS) company formerly known as Cerner), which affected patient data at multiple healthcare organizations and hospitals in the United States.

See also: CISA adds Adobe and Oracle vulnerabilities to KEV list

Information theft is the unauthorized acquisition, copying, or use of data or confidential information without the consent of its owner. It can involve personal data, trade secrets, credit card information, passwords, or other sensitive information. Information theft can have significant consequences such as: Financial loss (due to fraud), violation of privacy, loss of access to accounts (email, social media), and identity theft for malicious purposes.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS