Oracle Cloud and Oracle Health experience cyber incidents, sensitive data accessed
April 2025 brought even more – and bigger – cybersecurity news stories to note, potentially eclipsing the events seen in March , February and January .
Key points
- Multiple cyber incidents reported on April 22, 2025.
- Affected Oracle Cloud Classic and Oracle Health legacy environments.
- Hackers gained access to significant volumes of data.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Apr 22, 2025
- Updated
- Jul 22, 2026
- Confidence
- Medium
- Evidence
- 2 sources
Structured assessment
Signal analysis
This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch internet-facing systems, credential abuse and exploit activity.
- Source type: possible insider or internal misuse
Business impact
- Impact area
- Confidentiality
- Likely asset
- User or customer data, Server or cloud data store
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?
April 2025 brought even more – and bigger – cybersecurity news stories to note, potentially eclipsing the events seen in March , February and January . This month’s recap by SWK Technologies features an extended look at several top headlines and how they may impact your business, including breaches at Oracle and a financial services regulator, the effect of continuing budget and staff cuts at federal agencies, and attacks against public utilities. Continuing reading below to see the top cybersecurity stories for April and how they may affect you: Oracle Cloud Breaches May Have Exposed Millions of Files Oracle Cloud experienced multiple cyber incidents this year , although the company itself has denied that its greater cloud-based ecosystem is at risk. In an email to customers, Oracle stated “unequivocally” that the OCI (Oracle Cloud Infrastructure), the global network from which its various services are provided from, was itself not compromised and current users should be safe. The attacks ostensibly only affected legacy environments on servers belonging to “Oracle Cloud Classic” and Oracle Health, which are supposedly unconnected to the larger OCI ecosystem. In both of these cases, the hackers breached the ostensibly legacy servers and gained access to significant volumes of data – up to 6 million records from OCC alone – and demanded a ransom from Oracle on the threat of releasing the files publicly, though the FBI is currently investigating at least the Oracle Health incident. Almost simultaneously with this news was the release of hundreds of security patches by Oracle to address several vulnerabilities found in different systems, including some cloud services. Also concurrent with these incidents, several government institutions – including the U.S. Army, Department of Agriculture and The National Gallery of Art – announced contracts for cloud-based services from Oracle, even as such spending comes under scrutiny from the current Trump administration (more on that below). Oracle is a near-ubiquitous provider of technology solutions and services between databases and other software systems as well as their cloud environments, present in many popular digital architectures from coding scripts to ERP platforms. CVE Program for Bug Reporting Avoids Shutdown MITRE’s Common Vulnerabilities and Exposures (CVE) program , the industry standard for tracking and identifying security vulnerabilities, warned it may be at risk of having to cease operations due to a potential expiration of U.S. government funding on April 16, 2025. Professionals around the world working in cybersecurity, IT, software development and more have relied on these CVE warnings for years to quickly identify and address bugs throughout different systems and networks , preventing exploitation of critical applications by bad actors. As the greater infosec community and media panicked over the implications, CISA (Cybersecurity and Infrastructure Security Agency), the main federal agency in charge of cyberspace security, issued an 11-month contract extension for MITRE mere hours before the deadline. Though the ostensible information security apocalypse was narrowly avoided at the almost literal 11 th hour, there remains the real possibility that the CVE program will lose funding within the next few years. CISA continues to be a prime target of spending and job cuts by the Trump administration and DOGE, and the entire process around the budget reduction has been at best confusing (including rehires of fired or laid off personnel ). With accusations against Musk and his team of a fundamental lack of understanding of the cybersecurity demands of government – including a recent whistleblower complaint alleging major negligence – and continuing chaos involving current and former agency staff, it does not seem likely that CISA will survive this current term completely intact, raising the question of who will be in charge of keeping the CVE reporting up and running. MITRE, a nonprofit organization, is itself essentially a legacy holdover from when the Massachusetts Institute of Technology (MIT) spearheaded the program, and observers have already called for others to take over its responsibilities in a more collaborative methodology. However, this raises its own questions about the future of the program if ownership passes from an ostensibly neutral party funded by the U.S. government to other actors with different obligations, especially given the current global political climate. Big Banks Stop Disclosing Info After Regulator Hacked Multiple overlapping cybersecurity news stories wrapped up in one may have sweeping implications for regulation in the industry as several banks react to the fallout of a major breach discovered at the Office of the Comptroller of the Currency (OCC) . Part of the U.S. Treasury Department and responsible for overseeing the national banking system (including both domestic and foreign institutions), the OCC reported in early April 2025 that it had uncovered “a major information security incident” after investigations revealed unauthorized access of over 100 email accounts in its network. Both internal and third-party reviews by cybersecurity experts identified sensitive information contained in the compromised messages, which had been accessed by the hackers within at least a year before being discovered by February 2025. If this incident did not already bring its own wide-reaching implications already, the market reaction just further cemented the severity of the situation, with JPMorgan Chase, the Bank of New York Mellon and Bank of America reportedly “halting” sending information to the OCC . Other banks and credit unions are also reported to be potentially considering responsive action, although these rumors are unconfirmed and the only clear information so far is that Citigroup is continuing to share data under a stricter consent order resulting from a penal decision in 2024 . Though various media outlets indicate that the sharing pause is not total, the response itself creates an interesting precedent within the financial services industry and others. This news comes even as bipartisan efforts try to promote better reporting and data sharing between government and private institutions , highlighting the importance of collaboration and transparency in limiting the damage of cybercrime. April 2025 Data Breaches: 4 Million SSNs Leaked, 23M+ in Settlements Stay up to date with Pomerium news and announcements. You have successfully joined our subscriber list.
When was this signal reported?
Shadow Tier lists Apr 22, 2025 as the signal date.
Which organization is connected to this signal?
Oracle is the organization connected to this public signal.
Explore Oracle