Situation Overview
On the 21st of March 2025 reporting emerged suggesting that Oracle Cloud had been impacted by a largescale data breach, a report that Oracle denied.
The leak is being advertised of the dark-web marketplace “Breach Forums”, where a newly registered account, identified as ‘rose87168’ claims to have stolen over 6 million records from over 140k organisations. Given the lack of provenance of the account it held a low reputation. However, following denials by Oracle of any such breach, the threat actor substantiated their claims on 25th March 2025 by sharing 10,000 lines of data, which have subsequently been independently verified by security researchers and impacted and identifiable parties.
Security researchers investigating the claims identified that the platform was vulnerable to CVE 2021-35587. A Remote Code Execution vulnerability which the threat actor has since confirmed as being the cause of the exploit.
In an update shared on the 25th of March 2025, 10,000 lines of data had been shared with independent security investigators, likely chosen by the threat actor to assist in verifying the breach credibility to counter the denial claims made by Oracle.
What data has been leaked?
According to the dark web forum posting, the leaked data allegedly contains the following:
Lightweight directory access protocol (LDAP) database
- Names
- Emails
- Roles
- Potential hashed passwords
Identity and Access Management (IAM) database
- Names
- Emails
- User access privileges
- System configs
The leak also reportedly contains encrypted SSO passwords Enterprise Manager Java Platform Security (JPS) keys.
Breach Checker
A free tool has been made available by CloudSEK to help organisations identify if they may have been impacted.
Incident Response Recommendations
With Oracle denying the breach it is challenging to determine whether or not the vulnerability/exploit has been remediated and if any other persistence mechanisms have been identified and eradicated. In short, it is not clear if the incident is contained.
Protection/mitigation actions that organisations can carry out include:
- Rotate corporate domain and Oracle cloud credentials for users with access to oracle cloud, ensuring the credentials are unique for each environment and that MFA is enabled wherever possible.
- Cycle the credentials for any domain accounts that have access to the Oracle cloud platform
- Change the credentials for any Oracle cloud accounts (keeping the credentials different from any domain credentials where possible)
- Ensure MFA is in place wherever possible.
- Cycle any other authentication token/hash/certificate used to authenticate/access with the cloud platform.
- Request that Oracle cycle the tenancy ID and the tenancy name to prevent someone from trying to repeat the breach and specifically targeting your tenancy.
- Remain engaged with your Oracle account manager / point of contact, to try and ascertain their interpretation of events, actions, activities, exposer, etc.
Organisations should also be prepared to repeat the above again if/when the breach is confirmed and believed to be contained.
Impact
If the claims are true, thousands of Oracle Cloud customers could be affected, with sensitive data potentially exposed and sold on cyber-crime forums.
It is recommended that organisations who are potentially impacted review the data contained within the Oracle tenancy for items deemed to be within regulatory reporting frameworks, intellectual property, and where credentials may have further cross-platform access.
This understanding will help to guide business leaders in understanding the risk/potential exposure. It will also provide direction with regards to informing decision making as to how to proceed where negotiations may be considered necessary, as well as any potential regulatory or legal implications.
Quorum Cyber Threat Intelligence Follow-up Actions
The Quorum Cyber Threat Intelligence Team is monitoring the evolving situation closely and will provide updates as notable events occur.
Source













