Oracle Cloud Breach: What The Evidence Really Shows

27 March 2025by ZenaA

In March 2025, reports surfaced of a major breach involving Oracle Cloud’s infrastructure, potentially impacting over 140,000 companies. The incident has triggered intense debate between cybersecurity researchers and Oracle, raising urgent questions about cloud security, vendor accountability, and the protection of sensitive enterprise data

The Breach Allegations

On March 21, 2025, CloudSEK’s XVigil team reported that a threat actor had exfiltrated over six million records from Oracle Cloud’s Single Sign-On (SSO) and LDAP systems. Leaked data reportedly included:
• Java KeyStore (JKS) files
• Encrypted SSO and LDAP passwords
• Key files and Enterprise Manager JPS (Java Process Status) keys

The attacker allegedly targeted Oracle’s login endpoint at login.us2.oraclecloud.com

Further investigation revealed the attacker — known as “rose87168” — may have exploited CVE-2021-35587, a critical vulnerability in Oracle Fusion Middleware’s OpenSSO Agent

This flaw, despite being patched in 2021, remained active in Oracle’s systems, allowing unauthenticated access to Oracle Access Manager and potentially enabling remote code execution.

Oracle’s Response

Oracle has denied any breach. A spokesperson stated:
“There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data.”

However, Oracle acknowledged that certain files were uploaded to their servers, creating ambiguity around the incident’s true scope.

Evidence from Independent Researchers

Despite Oracle’s denials, multiple independent researchers and cybersecurity firms have uncovered evidence that suggests a real breach may have occurred

1. Validation of Exposed Data
Security experts reviewed sample data from the leak and confirmed its authenticity. Several affected Oracle Cloud customers verified that the credentials were legitimate and granted access to sensitive environments

2. Exploited Endpoint Still Active
Researchers found that the compromised login endpoint (login.us2.oraclecloud.com) remained operational as recently as February 17, 2025 — and was running outdated components at the time

3. Monetization and Threat Actor Activity
The attacker reportedly:
• Demanded payment from affected companies
• Offered bounties to assist in decrypting credentials
• Offered breached data for sale on BreachesForum

Evidence suggests encrypted passwords and cryptographic keys were part of the breach. Analysts suspect either brute-force decryption or insider help was used to extract credential data

 

The Oracle Breach Allegations

 

What This Means for Cloud Security

This incident underscores critical vulnerabilities in cloud environments — particularly in authentication systems. When a widely used platform like Oracle Cloud is compromised, thousands of tenants are exposed to cascading risk

How to Protect Your Organization

1. Patch Management
Ensure that CVE-2021-35587 and similar vulnerabilities are patched. Outdated components are a prime target

2. Credential Rotation
Immediately reset JKS keys, SSO/LDAP passwords, and JPS keys. Enforce Multi-Factor Authentication (MFA) for all privileged accounts

3. Log and Access Auditing
Continuously audit login attempts, especially to high-risk endpoints. Look for unusual patterns and failed authentications

4. Threat Monitoring
Use tools like Orca Cloud Security to identify misconfigurations and prioritize risks using AI-driven scoring

5. Dark Web Monitoring
Monitor for leaked credentials, ransom demands, and bounty offers. Attackers may attempt to sell your organization’s data.

How Wizard Cyber Can Help

Wizard Cyber provides:

• Managed Microsoft Sentinel
• CYBERSHIELD XDR
• 24/7 Managed Detection and Response (MDR)
We help organizations proactively detect breaches, monitor for dark web activity, and strengthen identity security. Our global SOC operates around the clock to protect your infrastructure and data.

🔍 Check if your domain appears in the Oracle breach:
👉 Use our free breach checker

Conclusion

Oracle denies a breach, but the technical evidence and third-party validation tell a different story. Regardless of the final verdict, this case serves as a powerful reminder of how fast threat actors evolve — and why cloud environments must be continuously hardened, monitored, and patched

Breach or not, the lesson is clear: Zero trust, visibility, and proactive defense aren’t optional anymore

CYBERSECURITY READINESS

Strengthen Your Cyber Defences Today

As cyber threats grow more complex, proactive detection is no longer optional.

With Wizard Cyber’s Microsoft expertise, organizations can transform their security posture and gain real-time visibility across all endpoints.

Start your journey to smarter, faster cybersecurity today.

EXPLORE MORE

Related Blogs & Insights

Discover blogs that deepen your knowledge and accelerate your security strategy.

ZenaA

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation