CSIDB logo
Incident

Oracle Corporation

Incident posture

Attack window
Mar 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:32

Linked entities

Victim
Oracle Corporation
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
2024
Discovered
Undetermined
Disclosed
Apr 2025
Resolved
Pending

Summary

A threat actor allegedly breached Oracle Corporation's Cloud Platform via a login endpoint, reportedly compromising over 140,000 tenants and claiming to exfiltrate around 6 million records. In a related intrusion disclosed separately, an attacker accessed a legacy environment that had not been in use for eight years, stealing old client log-in credentials—some dating to as recently as 2024—which Oracle advised posed limited risk. The cloud computing company notified affected customers, confirmed the incident was separate from a previously disclosed healthcare-sector breach, and stated that the FBI along with CrowdStrike were investigating, while the attacker sought an extortion payment.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early 2025, Oracle Corporation faced a cybersecurity incident involving its cloud platform that was later characterized in a Tokio Marine HCC International report as an alleged supply-chain breach. According to the Tokio Marine HCC report, which examined ten of the most significant cyber incidents of 2025, the breach reportedly affected over 140,000 tenants, with threat actors claiming to have exfiltrated approximately six million records. The report described the data breach as having been achieved via the login endpoint of Oracle's Cloud Platform. The incident was listed among incidents that illustrated how ransomware, technology supply-chain compromise, and cloud infrastructure concentration continue to drive systemic cyber risk for organizations worldwide. The inclusion of the Oracle incident in this top-ten list indicated its significant operational disruption, financial impact, and broader implications for the global digital ecosystem.

Prior to its inclusion in the Tokio Marine HCC annual report, details of the Oracle incident had emerged in April 2025 through reporting by Bloomberg News, which was subsequently covered by Reuters. According to the Bloomberg report cited by Reuters, Oracle informed customers that a hacker had broken into a computer system and stolen old client log-in credentials. The report indicated that an unidentified person had begun attempting to sell data online that was stolen from the cloud servers of the Austin, Texas-based company as early as the preceding month. Oracle staff acknowledged to some clients that an attacker had gained access to a legacy environment, and the company informed customers that the system had not been in use for eight years. Oracle stated that the stolen client credentials therefore posed little risk, though the stolen data included Oracle customer log-in credentials from as recently as 2024. The cloud computing company told customers that this data breach was separate from a hacking incident that it had previously flagged to some healthcare customers in the month prior, making it the second cybersecurity breach that the software company had acknowledged to clients within a short period.

The response to the incident involved coordination with external cybersecurity and law enforcement entities. According to the Bloomberg report, Oracle told some clients that the Federal Bureau of Investigation and cybersecurity company CrowdStrike Holdings were investigating the incident. The report also noted that the attacker had sought an extortion payment from the company. At the time of the initial Bloomberg and Reuters reporting, Oracle did not immediately respond to a request for comment, while a CrowdStrike spokesperson referred inquiries back to the cloud company. The compromised login endpoint and the alleged exfiltration of millions of records across over 140,000 tenants represented a significant scale of exposure, with the threat actors claiming responsibility for obtaining approximately six million records through the breach.

Sources

Sources available to members: 2 sources.

CSIDB