Massive Oracle Cloud Breach: 6M Records Exposed, 140k+ Tenants Risked

Oracle Cloud breach exposed 6M records from 140k+ tenants. Learn how attackers exploited vulnerabilities and steps organizations must take to secure data.

執筆者
Sunny Yadav
Sunny Yadav
Mar 24, 2025
2 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

A sophisticated supply chain hack targeting Oracle Cloud has exfiltrated a staggering 6 million records.

CloudSEK’s XVigil uncovered that threat actor “rose87168” began selling the stolen data on March 21. The breach, exploiting a vulnerability in Oracle’s cloud infrastructure, now endangers over 140,000 tenants and has raised serious questions about cloud security practices.

Incident discovery and exploitation

According to CloudSEK’s analysis, the threat actor claimed to have breached the subdomain login.us2.oraclecloud.com — an endpoint once hosting Oracle Fusion Middleware 11G. The initial access was gained by hacking the login endpoint (login.(region-name).oraclecloud.com), where sensitive single sign-on (SSO) and LDAP credentials were stored.

The compromised database contains approximately 6 million lines of data, including critical assets such as JKS files, encrypted SSO passwords, key files, and enterprise manager JPS keys. The attacker even offered an incentive to those who could help decrypt or crack these credentials and has been actively reaching out to affected organizations demanding a “fee” to remove their data.

Vulnerability analysis and exploit details

  1. The breach appears to be linked to a well-known vulnerability — CVE-2021-35587 — which affects Oracle Access Manager (OpenSSO Agent) in Oracle Fusion Middleware. 
  2. According to FOFA data, the vulnerable endpoint, last updated on Sept. 27, 2014, allowed an unauthenticated attacker network access via HTTP.
  3. This easily exploitable flaw enabled a complete compromise of Oracle Access Manager, underscoring how outdated configurations and poor patch management can lead to large-scale security failures.
  4. The fact that the affected subdomain was captured on the Wayback Machine in February 2025 further points to the longstanding vulnerability present in legacy Oracle systems.
Advertisement

Expert analysis and the broader cybersecurity context

Cybersecurity analysts have long warned that the rapid adoption of cloud technologies can outpace the implementation of necessary security frameworks. This incident reinforces that message.

Experts argue that cloud services offer scalability and flexibility but introduce complex security challenges that require continuous vigilance and proactive defense strategies.

The consequences of this breach are severe. Beyond mass data exposure, there are heightened risks of credential compromise, corporate espionage, and potential extortion. 

Organizations now face additional challenges: besides safeguarding sensitive data, they must contend with possible ransom demands from threat actors. Immediate mitigation measures include:

  • Resetting passwords, particularly for privileged LDAP accounts.
  • Rotating tenant-level credentials.

Affected organizations should also regenerate certificates and secrets linked to compromised configurations, audit logs for unusual activity, and implement enhanced monitoring.

Explore the best database security solutions to protect your sensitive business and customer data from unauthorized access.

Sunny Yadav

Sunny Yadav

Content Writer

Sunny is a content writer for eSecurity Planet (eSP) with a bachelor’s degree in technology and experience writing for leading cybersecurity brands like Panda Security, Upwind, and Vanta. At eSP, he covers the latest news on cyberattacks, cryptography, data protection, and emerging threats and vulnerabilities. He also explores security policies, governance, and endpoint and mobile security. Sunny enjoys hands-on testing, rigorously evaluating tools to assess their capabilities and real-world performance. He also has extensive experience working with AI tools like ChatGPT and Gemini, experimenting with their applications in cybersecurity, content creation, and research.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。