A large dataset has recently surfaced online, allegedly containing information linked to organizations that interacted with Oracle’s support and communication systems. The leak, attributed to a threat actor known as “rose87168”, includes thousands of corporate domains and related contact details.
The exposed data is reported to include:
-
Corporate email addresses
-
Contact names
-
Metadata from support communications
-
Organization names and domains
While the origins of the leak are still under investigation, Oracle has publicly denied any breach of their systems, stating that no unauthorized access has occurred on their end. However, the presence of real corporate data in the leak has raised concerns within the cybersecurity community about the potential misuse of this information for phishing or social engineering attacks.
Our lookup tool allows you to input your company domain and check if it’s included in the leaked dataset. If a match is found, you’ll have the option to receive an email report with further details and recommended actions to help secure your organization.
This tool checks if your domain is part of a
140,000-record list shared by a threat actor who claims to have accessed Oracle Cloud infrastructure in 2025.
Even if your company doesn’t officially use Oracle, your domain might still appear in the list — for example, if someone signed up using a company email address.