Oracle denies cloud breach as researchers back hacker's six million record claim

Organization
Oracle
Exploit
Hacking
Industry
Technology

In late March 2025 a threat actor using the handle rose87168 offered for sale what they described as six million records taken from Oracle Cloud's single sign-on infrastructure, naming more than 140,000 tenants as affected.

The listing, posted to a criminal forum, advertised Java keystore files, encrypted single sign-on and LDAP passwords, key files, enterprise manager JPS keys and OAuth2 keys. Researchers at CloudSEK said the actor had reached login.us2.oraclecloud.com, a live production sign-on server, and suggested the entry point was an undisclosed vulnerability or a misconfiguration in the OAuth2 authentication flow. Evidence indicated the actor had been active since January 2025.

Oracle rejected the account. A company spokesperson said there had been no breach of Oracle Cloud, that the published credentials were not for Oracle Cloud, and that no Oracle Cloud customer had lost data. The login.us2.oraclecloud.com server was taken offline without explanation.

Several security firms disputed the denial. The actor handed a sample of roughly 10,000 records to researchers. Kela counted 1,547 unique domain names and 1,510 distinct tenant identifiers in that sample, and Hudson Rock said three Oracle Cloud customers confirmed the entries matched real users and tenant IDs in their production environments. Some of the sample data dated to 2023, though the actor claimed to hold 2025 data as well. As of the end of March the dispute was unresolved and Oracle had not responded to the researchers' findings.

Sources