Back to overview
Oracle logo
oracle.com
Oracle
Confidence MediumMar 21, 2025oracle.com

Oracle Cloud Data Breach Allegations and Data Sale

PatternExternal actor · Hacking · Confidentiality impact

A threat actor, 'rose87168', claimed to have exfiltrated 6 million records from Oracle Cloud's Single Sign-On (SSO) and LDAP systems and began selling this data on hacking forums around March 20-21, 2025. The data allegedly included JKS files, encrypted SSO passwords, key files, and enterprise manager JPS keys, potentially impacting over 140,000 Oracle Cloud tenants. While Oracle initially denied a breach of its core cloud infrastructure, subsequent reports indicated private acknowledgments to some customers about a breach affecting older 'legacy environments'.

Signal date
Mar 21, 2025
Updated
Jun 26, 2026
Confidence
Medium
Sources
5 sources

Signal context

First seen: Mar 21, 2025

Last updated: Jun 26, 2026

Status: Public signal

Key points

  • Threat actor 'rose87168' claimed to have stolen 6 million records.
  • Data from Oracle Cloud's SSO and LDAP systems put up for sale on hacking forums.
  • Exposed data included JKS files, encrypted SSO passwords, key files, and enterprise manager JPS keys.

Signal analysis

Beta

It helps compare this signal with other published signals without treating the labels as final determinations.

Affected organization
Oracle logo
Oracle

Likely country: 🇺🇸 United States

inferred from source domains

    Threat source
    Hacking activity

    Watch internet-facing systems, credential abuse and exploit activity.

    • Source type: outside the affected organization
    Business impact
    Potential data exposure

    Impact area: Confidentiality

    Likely asset: User or customer data, Server or cloud data store

    Trend context
    69 signals with similar action pattern
    • 1 signal in the same sector
    • 90 signals with the same likely impact area
    • 1 signal linked to this organization/domain
    Mentioned entities
    OracleData DisclosureOracle CloudSingle Sign-OnSSOLDAPJKSJPSWhile OracleThreat

    External sources

    Related signals

    Grouped by why the signal is relevant.

    oracle.com logoOracleJun 10, 2026
    Same companySame action patternSame impact area

    Oracle PeopleSoft Zero-Day Exploited by ShinyHunters, Advisory Published

    Oracle published a security advisory on June 10, 2026, for CVE-2026-35273, a critical remote code execution flaw in PeopleSoft Enterprise PeopleTools. This vulnerability was actively exploited as a zero-day by the ShinyHunters cybercrime group in a campaign that ran from May 27 to June 9, 2026. The attacks compromised over 100 organizations, primarily colleges and universities, leading to data theft.

    nifty.com logoNiftyJun 28, 2026
    Same action patternSame impact area

    NIFTY Corporation Affected by KDDI Corporation Data Breach

    NIFTY Corporation, a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. NIFTY Corporation customers' email addresses and passwords may have been compromised.

    biglobe.ne.jp logoBiglobeJun 28, 2026
    Same action patternSame impact area

    BIGLOBE Inc. Affected by KDDI Corporation Data Breach

    BIGLOBE Inc., a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. BIGLOBE Inc. customers' email addresses and passwords may have been compromised.

    stnet.co.jp logoStnetJun 28, 2026
    Same action patternSame impact area

    STNet, Inc. Affected by KDDI Corporation Data Breach

    STNet, Inc., a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. STNet customers' email addresses and passwords may have been compromised.

    kddi-web.com logoKddi WebJun 28, 2026
    Same action patternSame impact area

    KDDI Web Communications Customer Data Affected by KDDI Email System Breach

    KDDI Web Communications, a subsidiary of KDDI, was impacted by the data breach in KDDI Corporation's email system, disclosed on June 28, 2026. The incident, caused by a third-party software vulnerability, led to the potential exposure of up to 14.2 million email addresses and passwords belonging to customers across six Japanese ISPs, including KDDI Web Communications.

    jcom.co.jp logoJcomJun 28, 2026
    Same action patternSame impact area

    JCOM Co., Ltd. Affected by KDDI Corporation Data Breach

    JCOM Co., Ltd., a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. JCOM customers' email addresses and passwords may have been compromised.