...

Oracle Faces Backlash Over Alleged Cloud Security Breach and Data Exposure.

Oracle is under intense scrutiny after reports of two Oracle data breach emerged within one week. Despite the growing controversy, the company has yet to publicly acknowledge the full extent of the incidents.

Cybersecurity Researcher Exposes Cloud Vulnerabilities

On March 20, 2025, a cybersecurity researcher claimed access to Oracle login systems tied to its cloud services. The exposed data included:

  • Encrypted SSO passwords
  • LDAP credentials
  • Security certificates
  • Employee personal records

Oracle denied any breach within its cloud infrastructure, stating no customer data was compromised. However, analysts found that the leaked data matched live production environments used by real clients.

Root Cause: CVE-2021-35587 Exploitation

Experts traced the breach to CVE-2021-35587, a vulnerability in Oracle Access Manager that permits HTTP-based remote exploitation. Though patched in 2022, Oracle allegedly failed to update its own systems, leaving clients exposed.

Healthcare Clients Impacted in Second Breach

In a separate incident reported around February 20, 2025, Oracle notified healthcare clients that attackers may have accessed patient data using stolen credentials. This raised serious concerns over Oracle’s internal security protocols.

Legal Repercussions and Class-Action Lawsuit

A federal lawsuit was filed in West Texas accusing Oracle of:

  • Negligence
  • Breach of contract
  • Failure to notify affected customers in a timely manner

The suit seeks class-action status and demands compensation along with stronger cybersecurity safeguards for customer data.

Transparency Under Fire

Critics argue that Oracle is attempting to minimize its liability by using technical language and differentiating between Oracle Cloud and Oracle Cloud Classic. Researchers also allege that Oracle tried to remove breach evidence from public archives.

Call for Stronger Cloud Provider Accountability

This incident underscores the critical need for:

  • Timely vulnerability patching
  • Proactive risk management
  • Transparent communication with affected customers

As reliance on cloud services increases, organizations must demand accountability and enhanced security protocols from service providers like Oracle.

Conclusion

The Oracle data breach controversy highlights serious issues in cloud infrastructure security. With legal and reputational consequences mounting, businesses are urged to strengthen vendor risk assessments and implement zero-trust frameworks to mitigate future threats.

https://grctechinsight.com/2025/03/30/oracle-faces-backlash-over-alleged-cloud-security-breach-and-data-exposure/

Must Read

Identity Acquisition Strengthens BarracudaONE Security.

Identity Acquisition Strengthens Enterprise Security Strategy Barracuda Networks has completed...

Huntress Ransomware Report CitrixBleed Exploits.

Huntress Ransomware Exposes Critical Enterprise Security Risks Security researchers have...

BLOCK8.AI : Building the Future of Penetration Testing Through AI and Human Expertise

As organisations continue expanding their digital operations across cloud...

Keyfactor Investment Strategic $1B Growth Deal.

Keyfactor Investment Strengthens Enterprise Trust Infrastructure Keyfactor Investment highlights the...

Cyber GRC Rapid7 Launches Unified Compliance Platform.

Rapid7 has announced the early access launch of its...

Topics

Identity Acquisition Strengthens BarracudaONE Security.

Identity Acquisition Strengthens Enterprise Security Strategy Barracuda Networks has completed...

Huntress Ransomware Report CitrixBleed Exploits.

Huntress Ransomware Exposes Critical Enterprise Security Risks Security researchers have...

BLOCK8.AI : Building the Future of Penetration Testing Through AI and Human Expertise

As organisations continue expanding their digital operations across cloud...

Keyfactor Investment Strategic $1B Growth Deal.

Keyfactor Investment Strengthens Enterprise Trust Infrastructure Keyfactor Investment highlights the...

Cyber GRC Rapid7 Launches Unified Compliance Platform.

Rapid7 has announced the early access launch of its...

AI PenetrationTesting Launches Agentic Pentest.

AI PenetrationTesting Transforms Modern Cybersecurity Cybersecurity teams continue to face...

Halcyon Dell Launches Ransomware Resilient PCs.

Halcyon dell Strengthens Enterprise Cybersecurity Ransomware remains one of the...

Acronis MDR Expands Cybersecurity Capabilities for MSPs.

Acronis MDR Strengthens Managed Security Services Acronis MDR helps managed...

Related Articles

Seraphinite AcceleratorOptimized by Seraphinite Accelerator
Turns on site high speed to be attractive for people and search engines.