SHARE
Facebook X Pinterest WhatsApp

Oracle’s Breach Exposes Credentials Despite Denials

According to Bloomberg, the compromised environment hasn’t been active for eight years, and the stolen credentials are no longer current.

Written By: Allison Francis
Apr 7, 2025
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Oracle has acknowledged to customers that hackers recently breached a dormant “legacy” system and stole outdated login credentials. According to Bloomberg, the compromised environment hasn’t been active for eight years, and the stolen credentials are no longer current.

Oracle was quick to assure clients that the compromised data was outdated and non-sensitive, but evidence suggests otherwise—the hackers have posted even more recent records from 2025 on a hacking forum.

Oracle has brought in CrowdStrike and the FBI to investigate the incident.

According to cybersecurity firm CybelAngel, Oracle disclosed to clients that attackers breached their Gen 1 (Oracle Cloud Classic) servers as early as January of this year, exploiting a 2020 Java vulnerability to install a web shell and other malware.

Breach details and timeline

The breach, discovered back in February, apparently involved the theft of data from Oracle Identity Manager (IDM), including user emails, usernames, and hashed passwords.

This breach discovery follows an incident in March when a malicious actor using the alias “rose87168” offered 6 million stolen data records for sale on BreachForums. The seller provided sample files containing database content, LDAP information, and a client list as evidence, claiming they were stolen from Oracle Cloud’s federated SSO login servers.

Around the same time, BleepingComputer reported that a hacker claimed to have stolen data from Oracle Cloud servers. Oracle consistently denied any cloud breach in statements to the press, stating, “There has been no breach of Oracle Cloud. The published credentials are not for Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data.”

According to Bloomberg, Oracle notified an undisclosed number of customers about the breach this week.

Careful wording and continued denials

The hackers reportedly stole credential data, including usernames, passkeys, and encrypted passwords.

Oracle continued to deny the breach even after evidence emerged showing the hacker had uploaded a file containing their email address to one of Oracle’s servers. This URL was later removed from Archive.org (though an archive of the archive still exists).

Oracle has consistently denied reports of an Oracle Cloud breach in its press statements since the incident came to light. This statement is technically accurate, as Oracle informs customers that the breach affected an older platform called Oracle Cloud Classic.

“Oracle rebadged old Oracle Cloud services to be Oracle Classic. Oracle Classic has the security incident,” cybersecurity expert Kevin Beaumont said this week. “Oracle are denying it on ‘Oracle Cloud’ by using this scope—but it’s still Oracle cloud services that Oracle manage. That’s part of the wordplay.”

Discover security articles covering topics like how to protect systems, networks, and data from cyber threats through measures via encryption, firewalls, and access controls. We provide expert insights into ensuring confidentiality, integrity, and availability of information.

thumbnail Allison Francis

Allison is a contributing writer for Channel Insider, specializing in news for IT service providers. She has crafted diverse marketing, public relations, and online content for top B2B and B2C organizations through various roles. Allison has extensive experience with small to midsized B2B and channel companies, focusing on brand-building, content and education strategy, and community engagement. With over a decade in the industry, she brings deep insights and expertise to her work. In her personal life, Allison enjoys hiking, photography, and traveling to the far-flung places of the world.

Recommended for you...

GoTo Pulse Survey Shows AI Promise, Highlights Gaps to Fill
Victoria Durgin
Aug 19, 2025
Deepgram Teams With AWS on Voice AI Deployment
Jordan Smith
Aug 19, 2025
Excendio Advisors Q&A: How to Prepare Your MSP for M&A
Victoria Durgin
Aug 19, 2025
Infosys’ $153M Versent Deal to Drive AI in Australia
Allison Francis
Aug 18, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.