Oracle Cloud Hit By Biggest Supply Chain Attack of 2025 – 140,000 Businesses At Risk

Oracle

March 23, 2025 A significant security breach has compromised Oracle Cloud’s infrastructure, exposing approximately 6 million records and placing over 140,000 businesses at risk. Cybersecurity firm CloudSEK identified the breach on March 21, 2025, attributing it to a threat actor known as “rose87168.”

The attacker is not well known in cybersecurity circles, but has demonstrated what experts are calling a “high level of technical sophistication.”

The compromised data includes sensitive authentication files such as Java KeyStore (JKS) files, encrypted Single Sign-On (SSO) passwords, key files, and Enterprise Manager Java Platform Security (JPS) keys. These elements are crucial for maintaining secure access within enterprise environments.

The attacker reportedly exploited a vulnerability in Oracle Cloud’s login interface, specifically targeting the subdomain login.us2.oraclecloud.com. This subdomain was associated with Oracle Fusion Middleware 11G, which has known vulnerabilities, including CVE-2021-35587. This particular flaw allows unauthenticated attackers to compromise Oracle Access Manager, potentially leading to a complete system takeover.

The threat actor has been active since January 2025 and is demanding payments from affected companies to remove their data from the compromised set. They have also offered incentives to individuals who can assist in decrypting the stolen SSO passwords or cracking the Lightweight Directory Access Protocol (LDAP) passwords.

The breach poses several risks:

  • Data Exposure: Sensitive authentication data could be used for unauthorized access or corporate espionage.
  • Credential Compromise: If decrypted, the stolen passwords could facilitate further breaches within Oracle Cloud environments.
  • Extortion: The attacker’s ransom demands place additional financial and reputational pressures on affected businesses.

CloudSEK advises organizations utilizing Oracle Cloud services to take immediate actions, including resetting passwords, updating security protocols, and monitoring for any unusual activities. Businesses can verify their exposure to this breach through CloudSEK’s dedicated portal:

https://exposure.cloudsek.com/oracle

Oracle has yet to release an official statement regarding the breach. Organizations are urged to remain vigilant and implement recommended security measures to mitigate potential threats arising from this incident.

 

Top Stories

Related Articles

December 23, 2025 South Korea will require facial recognition scans to open new mobile phone accounts. The new rule is more...

December 22, 2025 Apple is requiring iPhone users who have not upgraded to iOS 26 to update now after confirming more...

December 12, 2025 The United States has extradited a Ukrainian national accused of working with Russian-backed hacktivist groups that targeted more...

November 24, 2025 Google is rolling out its Gemini artificial intelligence assistant to vehicles equipped with Android Auto, promising a more...

Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com
Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn