1. Website Planet
  2. >
  3. News
  4. >
  5. Oracle Confirms Second Hacking Attack in a Month
Oracle Confirms Second Hacking Attack in a Month

Oracle Confirms Second Hacking Attack in a Month

Andrés Gánem Written by:
Maggy Di Costanzo Reviewed by: Maggy Di Costanzo
Last updated: April 17, 2025
Oracle, the world’s largest database management company, has confirmed a breach of its systems and exposure of old login credentials, as reported by Bloomberg. This is the second, seemingly unconnected, confirmed breach into the company’s records in less than a month.

On March 20, a hacker using the moniker “rose87168” published an offer on the popular hacking platform BreachForums to sell data linked to over 140,000 Oracle Cloud users.

According to an independent investigation by cybersecurity company CybelAngel, the exposed data includes email addresses, usernames, and passwords. Oracle claims that the dataset does not contain full Personally Identifiable Information (PII).

The hacker initially demanded $20 million in ransom from Oracle but later offered the data to forum users or sought to trade it for zero-day exploits.

In a statement to customers, Oracle initially denied the breach: “There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data.”

However, after the hacker published further information, samples, and other proof that backed up their claims, Oracle revised its stance.

In early April, the company began notifying clients that an attacker had breached a “legacy environment,” but added that the system hadn’t been in use for eight years. Oracle emphasized that the stolen credentials didn’t signify a major risk.

Speaking to Bloomberg, an anonymous source said that some of the login data dated back to 2024.

Posts by the hacker suggest they accessed even more recent information, possibly from 2025.

All communications between Oracle and affected customers have been entirely verbal, with no written records available. Oracle also claims that both the FBI and CrowdStrike Holdings, an independent cybersecurity firm, are looking into the breach.

This confirmation comes about a week after reports of another, reportedly unrelated, breach into the company’s healthcare branch, Oracle Health. The earlier hack affected multiple healthcare organizations across the US and exposed sensitive patient data.

Healthcare systems are an attractive target for ransomware attacks because of their patient’s vulnerable state and the quality of personal information. Earlier this year, the private rehabilitation clinic American Addiction Centers began notifying over 420,000 patients of a hack that compromised their PII.

Rate this Article
4.3 Voted by 4 users
You already voted! Undo
This field is required Maximal length of comment is equal 80000 chars Minimal length of comment is equal 10 chars
Any comments?
Reply
View %s replies
View %s reply
More news
Show more
We check all user comments within 48 hours to make sure they are from real people like you. We're glad you found this article useful - we would appreciate it if you let more people know about it.
Popup final window
Share this blog post with friends and co-workers right now:
1 1 1

We check all comments within 48 hours to make sure they're from real users like you. In the meantime, you can share your comment with others to let more people know what you think.

Once a month you will receive interesting, insightful tips, tricks, and advice to improve your website performance and reach your digital marketing goals!

So happy you liked it!

Share it with your friends!

1 < 1 1

Or review us on 1

3635996
50
5000
143200183