Cyb3rius
@cyb3rius
· Sep 1
How did Oracle Cloud get breached in March 2025?A threat actor called "rose87168" exploited a known vulnerability in Oracle Cloud's federated SSO servers, stealing JWT secret keys and API credentials from over 140,000 tenants.What happened: In late March 2025, the attacker breached Oracle Cloud's login and LDAP infrastructure, exfiltrating authentication data and encrypted SSO passwords across massive customer environments. They demanded a $100,000 ransom, and Oracle initially denied the incident before quietly acknowledging that sensitive data had been accessed.Key numbers: 140,000+ tenant environments affected$100,000 ransom demanded (unpaid)6 million records claimed exfiltrated by the attackerWhy it matters: Stolen JWT secret keys and API signing credentials let attackers forge authentication tokens, meaning they could impersonate legitimate enterprise users—not just read data.Bottom line: If Oracle can silently lose a hundred thousand tenants' credentials, treat every vendor's "secure by design" claim as a starting point, not a guarantee.
0