Oracle has firmly denied experiencing a security breach after a threat actor claimed to be selling 6 million data records allegedly stolen from Oracle Cloud’s federated SSO login servers.
“There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data,” Oracle stated in response to the allegations.
## The Hacker’s Claims
A threat actor using the handle “rose87168” posted multiple text files containing what they claim is sample data, LDAP information, and a list of affected companies allegedly stolen from Oracle Cloud’s SSO platform. As evidence, the hacker shared an Internet Archive URL showing they had uploaded a text file containing their ProtonMail address to a login.us2.oraclecloud.com server.
The threat actor is now attempting to sell the allegedly stolen data on the BreachForums hacking forum for an undisclosed price or in exchange for zero-day exploits. According to their claims, the data includes:
– Encrypted SSO passwords
– Java Keystore (JKS) files
– Key files
– Enterprise manager JPS keys
The hacker claims the data was stolen after breaching ‘login.(region-name).oraclecloud.com’ servers and states that while “SSO passwords are encrypted, they can be decrypted with the available files.”
## Alleged Breach Timeline
According to rose87168, they gained access to Oracle Cloud servers approximately 40 days ago and subsequently contacted the company after exfiltrating data from the US2 and EM2 cloud regions. The hacker claims they requested 100,000 XMR (Monero cryptocurrency) for information about the breach method, but alleges Oracle refused to pay.
When questioned about their methods, the threat actor claimed all Oracle Cloud servers use a vulnerable version with a public CVE that currently lacks a public proof-of-concept or exploit.
The validity of the data and breach claims remains unverified as investigations continue.
