• Sign in
  • Register

Lost your password?

A password will be sent to your email address.

Your personal data will be used to support your experience throughout this website, to manage access to your account, and for other purposes described in our privacy policy.

Close
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
Cyber Attack

Oracle Refutes Hacker’s Claim of Stealing 6 Million Records in Alleged Cloud Breach

ClickControl

Author

March 25, 2025

Published


# Oracle Denies Cloud Breach Despite Hacker’s Claims of Stolen Data

Oracle has firmly denied experiencing a security breach after a threat actor claimed to be selling 6 million data records allegedly stolen from Oracle Cloud’s federated SSO login servers.

“There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data,” Oracle stated in response to the allegations.

## The Hacker’s Claims

A threat actor using the handle “rose87168” posted multiple text files containing what they claim is sample data, LDAP information, and a list of affected companies allegedly stolen from Oracle Cloud’s SSO platform. As evidence, the hacker shared an Internet Archive URL showing they had uploaded a text file containing their ProtonMail address to a login.us2.oraclecloud.com server.

The threat actor is now attempting to sell the allegedly stolen data on the BreachForums hacking forum for an undisclosed price or in exchange for zero-day exploits. According to their claims, the data includes:

– Encrypted SSO passwords
– Java Keystore (JKS) files
– Key files
– Enterprise manager JPS keys

The hacker claims the data was stolen after breaching ‘login.(region-name).oraclecloud.com’ servers and states that while “SSO passwords are encrypted, they can be decrypted with the available files.”

## Alleged Breach Timeline

According to rose87168, they gained access to Oracle Cloud servers approximately 40 days ago and subsequently contacted the company after exfiltrating data from the US2 and EM2 cloud regions. The hacker claims they requested 100,000 XMR (Monero cryptocurrency) for information about the breach method, but alleges Oracle refused to pay.

When questioned about their methods, the threat actor claimed all Oracle Cloud servers use a vulnerable version with a public CVE that currently lacks a public proof-of-concept or exploit.

The validity of the data and breach claims remains unverified as investigations continue.

Keywords: Oracle Cloud breach, data security, SSO login servers, cybersecurity threat, hacker data theft, cloud security vulnerability

Share This Article
Tags: cloud security vulnerability cybersecurity threat data security hacker data theft Oracle Cloud breach SSO login servers
Previous Article Microsoft Edge for Business Unveils
Next Article andMe Declares Bankruptcy Why Experts
Curve Line
logo_white
Quick Links
  • Cybersecurity News
  • Video Guides
  • Shop
Company
  • Home
  • About us
  • Contact
  • Careers
  • Privacy Policy

(C) Copyright 2023-2026 ClickControl IT MSP & Cybersecurity, All Rights Reserved.