
Oracle has officially acknowledged that hackers stole and leaked credentials from what it describes as “two obsolete servers,” while emphasizing that its Oracle Cloud Infrastructure (OCI) remains secure. In email notifications to customers, the company stated unequivocally that no OCI customer environments were penetrated, no customer data was compromised, and no cloud services were interrupted.
“A hacker did access and publish user names from two obsolete servers that were never a part of OCI,” Oracle explained. “The hacker did not expose usable passwords because the passwords on those two servers were either encrypted and/or hashed.”
## Controversy Over Breach Classification
The incident first came to light in March when a threat actor using the handle “rose87168” offered 6 million data records for sale on BreachForums. While Oracle has consistently denied an “Oracle Cloud breach,” cybersecurity expert Kevin Beaumont suggests this is merely wordplay, noting that the affected systems were likely part of Oracle Cloud Classic, which Oracle has rebranded as a legacy service.
“Oracle rebadged old Oracle Cloud services to be Oracle Classic. Oracle Classic has the security incident,” Beaumont explained. “Oracle are denying it on ‘Oracle Cloud’ by using this scope — but it’s still Oracle cloud services that Oracle manage.”
## Timeline and Impact
One week prior to the public notification, Oracle privately acknowledged to some clients that attackers had breached a “legacy environment” last used in 2017. However, evidence suggests the compromised data is more recent, with samples from late 2024 and early 2025.
According to cybersecurity firm CybelAngel, Oracle informed customers that an attacker deployed a web shell and malware on Oracle Cloud Classic servers as early as January 2025. The breach, detected in February, reportedly involved theft of data from the Oracle Identity Manager database, including user emails, hashed passwords, and usernames.
## Additional Security Concerns
This incident follows another breach reported in January at Oracle Health (formerly Cerner), which affected patient data at multiple U.S. healthcare organizations. Sources indicate that a threat actor named “Andrew” is now extorting the affected hospitals, demanding millions in cryptocurrency to prevent the sale or leaking of stolen data.
Multiple Oracle customers have independently verified that samples of the leaked data contain valid information, contradicting Oracle’s initial characterization of the breach as involving only “non-sensitive old legacy data.”
