Data leak

Oracle Cloud (OCI) Infrastructure Breach β€” 6 Million Records, Login Credentials

πŸ“… 2025-01-01 🏒 Oracle Cloud Infrastructure (OCI) / Oracle Identity Manager / Oracle Access Manager πŸ”Ž CVE-2021-35587
Primary Source β†—

Incident Details

In March 2025, a threat actor known as ‘rose87168’ advertised on BreachForums the sale of approximately 6 million records allegedly stolen from Oracle Cloud’s federated SSO login servers. The attacker posted sample data and offered to sell the database for $200 million, or exchange it for information on decrypting the hashed passwords. Oracle initially denied the breach occurred, stating ‘Oracle Cloud has not experienced a security breach.’ However, multiple security researchers verified that the sample data appeared authentic, matching real Oracle Cloud customer domains and encrypted credentials. The attacker provided evidence including creating a specific file on an Oracle server and sharing a 2024-era archive.org URL of the targeted oracle.com subdomain (login.us2.oraclecloud.com) running an allegedly vulnerable version. The breach appeared to leverage CVE-2021-35587 β€” an Oracle Fusion Middleware Access Manager vulnerability β€” against a server that had not been patched. Oracle privately notified some customers of the breach despite public denial. The stolen data included Java KeyStore (JKS) files, encrypted SSO passwords, and LDAP hashes for Oracle Cloud customers. Multiple cybersecurity companies including CrowdStrike and CloudSEK confirmed elements of the breach. Oracle’s continued public denial while privately notifying customers drew significant criticism. The incident was investigated by the FBI and CISA.

Technical Details

Initial Attack Vector
A threat actor known as 'rose87168' claimed to have exploited a vulnerability in Oracle Cloud's login infrastructure (login.oracle.com / Oracle Identity Manager) to access Oracle's SSO and LDAP systems, exfiltrating approximately 6 million records including encrypted SSO passwords, LDAP password hashes, and JKS files
Vendor / Product
Oracle Cloud Infrastructure (OCI) / Oracle Identity Manager / Oracle Access Manager
CVE / GHSA References
CVE-2021-35587

Timeline

  1. 2025-01-01 Breach occurred
  2. 2025-03-20 Publicly disclosed
  3. 2025-03-31 Customers notified