In March 2025, reports surfaced of a major breach involving Oracle Cloud’s infrastructure, potentially impacting over 140,000 companies. The incident has triggered intense debate between cybersecurity researchers and Oracle, raising urgent questions about cloud security, vendor accountability, and the protection of sensitive enterprise data
The Breach Allegations
On March 21, 2025, CloudSEK’s XVigil team reported that a threat actor had exfiltrated over six million records from Oracle Cloud’s Single Sign-On (SSO) and LDAP systems. Leaked data reportedly included:
• Java KeyStore (JKS) files
• Encrypted SSO and LDAP passwords
• Key files and Enterprise Manager JPS (Java Process Status) keys
The attacker allegedly targeted Oracle’s login endpoint at login.us2.oraclecloud.com
Further investigation revealed the attacker — known as “rose87168” — may have exploited CVE-2021-35587, a critical vulnerability in Oracle Fusion Middleware’s OpenSSO Agent
This flaw, despite being patched in 2021, remained active in Oracle’s systems, allowing unauthenticated access to Oracle Access Manager and potentially enabling remote code execution.
Oracle’s Response
Oracle has denied any breach. A spokesperson stated:
“There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data.”
However, Oracle acknowledged that certain files were uploaded to their servers, creating ambiguity around the incident’s true scope.
Evidence from Independent Researchers
Despite Oracle’s denials, multiple independent researchers and cybersecurity firms have uncovered evidence that suggests a real breach may have occurred
1. Validation of Exposed Data
Security experts reviewed sample data from the leak and confirmed its authenticity. Several affected Oracle Cloud customers verified that the credentials were legitimate and granted access to sensitive environments
2. Exploited Endpoint Still Active
Researchers found that the compromised login endpoint (login.us2.oraclecloud.com) remained operational as recently as February 17, 2025 — and was running outdated components at the time
3. Monetization and Threat Actor Activity
The attacker reportedly:
• Demanded payment from affected companies
• Offered bounties to assist in decrypting credentials
• Offered breached data for sale on BreachesForum
Evidence suggests encrypted passwords and cryptographic keys were part of the breach. Analysts suspect either brute-force decryption or insider help was used to extract credential data
What This Means for Cloud Security
This incident underscores critical vulnerabilities in cloud environments — particularly in authentication systems. When a widely used platform like Oracle Cloud is compromised, thousands of tenants are exposed to cascading risk
How to Protect Your Organization
1. Patch Management
Ensure that CVE-2021-35587 and similar vulnerabilities are patched. Outdated components are a prime target
2. Credential Rotation
Immediately reset JKS keys, SSO/LDAP passwords, and JPS keys. Enforce Multi-Factor Authentication (MFA) for all privileged accounts
3. Log and Access Auditing
Continuously audit login attempts, especially to high-risk endpoints. Look for unusual patterns and failed authentications
4. Threat Monitoring
Use tools like Orca Cloud Security to identify misconfigurations and prioritize risks using AI-driven scoring
5. Dark Web Monitoring
Monitor for leaked credentials, ransom demands, and bounty offers. Attackers may attempt to sell your organization’s data.
How Wizard Cyber Can Help
Wizard Cyber provides:
• Managed Microsoft Sentinel
• CYBERSHIELD XDR
• 24/7 Managed Detection and Response (MDR)
We help organizations proactively detect breaches, monitor for dark web activity, and strengthen identity security. Our global SOC operates around the clock to protect your infrastructure and data.
🔍 Check if your domain appears in the Oracle breach:
👉 Use our free breach checker
Conclusion
Oracle denies a breach, but the technical evidence and third-party validation tell a different story. Regardless of the final verdict, this case serves as a powerful reminder of how fast threat actors evolve — and why cloud environments must be continuously hardened, monitored, and patched
Breach or not, the lesson is clear: Zero trust, visibility, and proactive defense aren’t optional anymore



