Oracle Cloud Data Breach Claim: What Is Confirmed, What Is Disputed and What to Do

A cybersecurity incident involving Oracle Cloud has surfaced, with a hacker claiming to have stolen authentication data for 6 million users. While Oracle denies any breach, multiple companies have confirmed the validity of leaked credentials. The hacker allegedly exploited CVE-2021-35587, a vulnerability in Oracle Fusion Middleware 11g, to gain access to LDAP and SSO login credentials. Despite Oracle's refusal to acknowledge the breach, evidence suggests that cloud authentication security was compromised, raising concerns about enterprise security practices. This blog provides a detailed analysis of the alleged breach, its potential impact, and security measures organizations should take to protect their cloud environments.

Mar 31, 2025 - 16:15
Updated: 8 days ago
103k
Oracle Cloud Data Breach Claim: What Is Confirmed, What Is Disputed and What to Do

Quick answer: In March 2025 a threat actor named rose87168 claimed to have stolen about six million records from Oracle's cloud sign-on infrastructure. Oracle denied a breach of Oracle Cloud, but later reporting said a legacy environment was affected. Details, including the claimed flaw CVE-2021-35587, are disputed, so check current official statements.

Key takeaways

  • The claim dates to March 2025, not 2026.
  • Oracle denied a breach of Oracle Cloud, but reporting later pointed to a legacy environment.
  • The actor's cited flaw, CVE-2021-35587, is a patched, older vulnerability, and its role is unconfirmed.
  • Inventory legacy systems, patch, rotate credentials and report incidents to CERT-In.

What was claimed

In March 2025 a threat actor using the name "rose87168" posted on a hacking forum claiming to have stolen data from Oracle Cloud's single sign-on and LDAP infrastructure. The post offered about six million records, said to include encrypted passwords, key files and tenant details, and demanded payment. An earlier version of this article gave the date as 2026, which was wrong. The incident dates to 2025.

Oracle's response, and why it was disputed

Oracle publicly denied that its Oracle Cloud had been breached and said the published credentials were not from Oracle Cloud. Several organisations and security researchers disputed this after examining sample data, and reporting later said Oracle had told some customers that an older, legacy environment had been affected. Oracle's wording drew criticism because it appeared to separate "Oracle Cloud" from the legacy systems involved. Because the facts were reported by several outlets and not all confirmed by Oracle, check the latest statements from Oracle, CISA and CERT-In before you quote any of this as settled.

The vulnerability behind the claim

The actor claimed to have exploited a flaw in Oracle Fusion Middleware, specifically Oracle Access Manager, tracked as CVE-2021-35587. It is a long-standing vulnerability with a patch available since 2021. The record is on the National Vulnerability Database. Whether this flaw was the actual entry point in the incident is the actor's claim, and has not been independently confirmed in the sources used here.

Why this matters even if details are disputed

  • Old systems stay exposed. A vulnerability that is years old can still be exploited if a server was never patched or retired.
  • Shared sign-in is a single point of risk. Stolen SSO material can affect many applications at once.
  • Vendor statements are not evidence. A "no breach" claim can be technically narrow. Customers should test their own exposure.
  • Credential material ages badly. Even hashed or encrypted passwords can be attacked offline.

What organisations should do

  1. Inventory systems, including legacy and forgotten ones, and retire what is not needed.
  2. Patch or mitigate known vulnerabilities, using the NVD and vendor advisories to prioritise.
  3. If you run Oracle Access Manager or related products, check vendor guidance and review logs for suspicious access.
  4. Rotate credentials, keys and certificates that could have been exposed, and enable multi-factor authentication.
  5. Monitor for your domain in leak reports and follow incident response procedure if you see it.
  6. Report incidents to CERT-In, which requires reporting of cyber incidents within set time limits for covered entities.

Lessons for defenders and learners

This case teaches vulnerability management, asset inventory and incident communication more than any single technique. For other recent breaches, see our write-ups on the Nokia data breach claim and the Samsung Germany breach.

Next steps

To learn how to manage vulnerabilities and respond to incidents, see the SOC analyst course.

Related reading

Frequently Asked Questions

In March 2025 an actor named rose87168 claimed to have stolen about six million records from Oracle's cloud sign-on infrastructure. Oracle denied a breach of Oracle Cloud, while later reports pointed to an affected legacy environment.

Oracle publicly denied a breach of Oracle Cloud. Later reporting said it told some customers that a legacy environment was affected. Statements vary, so check Oracle's, CISA's and CERT-In's latest updates before quoting.

The actor claimed to exploit CVE-2021-35587 in Oracle Access Manager, part of Fusion Middleware. It is an older vulnerability with a patch. Whether it was the actual entry point has not been independently confirmed.

The actor claimed about six million records including encrypted passwords, key files and tenant information. Some organisations said the sample data appeared valid, but the full scope has not been confirmed in the sources used.

Review vendor guidance, check logs for suspicious access, rotate credentials and keys that may be exposed, enable multi-factor authentication and monitor leak reports. Report incidents to CERT-In and follow the incident response plan.

It shows why asset inventory, patching old vulnerabilities and retiring legacy systems matter, and why a vendor's narrow denial is not proof of safety. It is a good case study in vulnerability management.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.