In March of last year, Bleeping Computer reported some shenanigans that strongly suggested a data breach at Oracle Cloud had occurred. An apparent hacker who went by rose87168 was releasing data that seemed to have been pried out of Oracle’s single sign-on system. At the time, according to Bleeping Computer, Oracle denied there was a breach, writing in a statement, “There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data.” There were, according to rose87168, 6 million exposed health records.
The following month, Bleeping Computer said it had learned that Oracle had apparently confirmed a breach, but at the time only in private, to some of the individuals involved. Oracle apparently wrote, “We are writing to inform you that, on or around February 20, 2025, we became aware of a cybersecurity event involving unauthorized access to some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud.” The fact that the legacy server was not part of the Oracle Cloud system could help explain why Oracle claimed to have not been breached.
On Monday, Bloomberg reported that the attorney general of Texas had released information claiming that 20 million people’s data was involved in the breach. The AG’s report said the exposed data included medical details, addresses, and Social Security numbers. Oracles medical clients include the Department of Defense and the Department of Veterans Affairs, Bloomberg notes.
The purpose of the hack, according to a Bloomberg source last year who was granted anonymity, was to hold data hostage and extract ransoms from U.S. medical providers.
Gizmodo reached out to Oracle for a statement. We will update this article if we hear back.