Texas AG Says Oracle Health’s 2025 Breach Affected 20M Individuals

A Texas AG filing says Oracle Health’s 2025 breach affected nearly 20 million people, while major questions about access and attribution remain.

Oct 7, 2026
3 minute read
Three-dimensional Oracle logo on a reflective blue surface with pink lighting against a dark background.

Oracle Health’s 2025 breach is back in focus, this time with a bigger story. Image: Unslpash/BoliviaInteligente

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Oracle Health’s 2025 breach affected nearly 20 million people, giving the incident a scale that had not previously been publicly established.

A new filing reported by Bloomberg attributes the figure to the Texas Attorney General, adding a concrete victim count to a breach already known to have exposed patient data at multiple healthcare organizations.

The attack dates back to early 2025, when compromised customer credentials were used to access legacy Cerner servers that had not yet been migrated into Oracle’s newer cloud environment.

How the Oracle Health breach unfolded

The incident began in January 2025, when attackers used compromised customer credentials to access legacy Cerner data servers and copy data to a remote server. 

Per a BleepingComputer report, unauthorized access began on or around Jan. 22, while Oracle did not identify the incident until about Feb. 20.

The incident became public in March, after BleepingComputer reported that an attacker going by the name rose87168 was releasing data that appears to be connected to Oracle Cloud. At the time, Oracle denied the breach, saying that its Oracle Cloud Infrastructure (OCI) wasn’t compromised.

The breach in question was later found to have involved legacy Cerner servers, whose data had not yet moved to Oracle. That distinction matters because Oracle had earlier acquired Cerner and folded the healthcare business into Oracle Health. Still, the compromised infrastructure remained part of the older Cerner environment during the transition.

Major questions remain unanswered

One would expect a breach that happened nearly 21 months ago to have a fairly complete technical post-mortem by now, but the Oracle Health incident still has some surprisingly large gaps.

We know attackers used compromised customer credentials to enter legacy Cerner servers. But the public record still doesn't explain how they obtained those credentials or why a customer credential provided access to data belonging to multiple healthcare organizations. 

There is also no explanation of exactly how much data was copied, even though, thanks to the Texas Attorney General, we are now learning it affected 20 million individuals.

The identities behind the operation are murky too. BleepingComputer linked the Oracle Health campaign to an actor known as Andrew after reports emerged that the actor tried to extort affected healthcare providers. At the same time, rose87168 was associated with a separate Oracle-related incident involving claims of stolen cloud data. No public evidence establishes that the two are the same actor or connected.

Advertisement

That leaves another major question unanswered: who actually carried out the Oracle Health attack, and what did investigators ultimately learn about the operation?

Nearly two years on, then, the scale of the breach is becoming clearer faster than the mechanics and attribution behind it.

Where does this leave affected individuals?

For the people caught in the breach, the problem is that much of the exposed information cannot simply be replaced. Names and Social Security numbers can be used for identity theft, while medical records pose a separate risk.

There is also a delay between the breach itself and some patients learning whether they were affected, although that was because law enforcement requested that patient notifications be delayed. LifeBridge, for example, received its list in September 2025,

For affected patients, CyPro says Oracle is offering complimentary credit monitoring. In addition to confirming with your healthcare provider, review your healthcare and insurance statements for suspicious activity and report anything you do not recognize.

If you think you may be affected and haven't received a notification, contact your healthcare provider to confirm whether they use Oracle Health and were affected.

Another risk is that the breach is getting renewed attention. Scammers can use the story itself to impersonate Oracle Health, hospitals, insurers, or other trusted organizations. So, anyone receiving a notification should verify it through the healthcare provider's official website or a trusted phone number rather than using contact details in an unsolicited message.

For affected patients, the new 20 million figure does not make the incident new again. It shows that the consequences are still unfolding long after the intrusion itself.

The breach is now clearer in scale than in cause. Until Oracle or investigators provide a fuller account of how the attackers gained access and what they ultimately took, significant questions about the incident will remain unresolved.

Other news: Progress patched four vulnerabilities in Telerik Fiddler Classic, including a high-severity flaw that could let a low-privilege local attacker execute unintended code with administrator privileges.

Joseph Chisom Ofonagoro

Joseph is a Technical Writer with about 3 years of experience in the industry, also advancing a career in cyber threat intelligence. He is passionate about the responsible use of technology, a passion that led him into cybersecurity. As an undergrad, he leads a novel community of technology enthusiasts at his school, NOUN, where he guides and shares resources for beginners in tech. His writing experience includes a diverse range of topics, from consumer tech to startups to tutorials. Additionally, he periodically shares case studies and research reports on cybersecurity on his social media pages.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.