---
title: "Alleged Oracle Cloud Supply Chain Attack: Six Million Records Stolen, 140K Companies Affected"
description: Critical Remote Code Execution Vulnerability in Veeam Backup & Replication (CVE-2025-23120)
image: https://www.coolspirit.co.uk/hubfs/website/images/heros/hybrid-cloud-storage-hero-image.jpg
---

# Alleged Oracle Cloud Supply Chain Attack

![](https://www.coolspirit.co.uk/hubfs/website/images/curves/hero/pngs/hero-curve-white.png)

## Alleged Oracle Cloud Supply Chain Attack: Six Million Records Stolen, 140K Companies Affected

 Written on: ** Mar 25, 2025 9:54:47 AM **

 Written by: ** Alex Raben **

 Topic

 [Data Security, COOLSPIRiT, Cyber Security, Arctic Wolf]

 Share this post:

This article provides situational awareness regarding a claimed breach impacting Oracle Cloud, allegedly affecting 140,000 companies. We strongly recommend reviewing the details to understand the situation and follow the recommendations to protect against potential impact.

** Summary**

On March 20, 2025, a Breach Forums user, "rose87168," claimed to have stolen six million records from Oracle Cloud’s SSO and LDAP services and offered the data for sale or in exchange for zero-day exploits. Breach Forums is a known marketplace for cybercriminals to trade stolen data and exploits. The threat actor's post included a list of 140,000 alleged impacted organisations, claiming the stolen records contained encrypted SSO and LDAP passwords, Java Keystore (JKS) files, key files, and enterprise manager JPS keys. However, the threat actor stated that they could not decrypt the stolen passwords.

The data was allegedly stolen by compromising 'login.(region-name).oraclecloud.com' Oracle servers. They further claimed to an independent news outlet that the breach targeted a vulnerable Oracle Cloud server affected by a publicly known CVE, though no public proof-of-concept (PoC) or exploit exists.

**Credibility of the Breach**

Oracle has denied the breach, stating to multiple media outlets that no Oracle Cloud customers experienced data loss or compromise.

The cybersecurity firm CloudSEK analysed the forum post, and despite Oracle’s denial of the breach, asserts that their investigation revealed a compromised production SSO endpoint that supports the forum member's claim. They suggest that the attack may have leveraged a known critical vulnerability in Oracle Fusion Middleware, possibly CVE-2021-35587. CloudSEK confirmed that the affected server (login.us2.oraclecloud.com) was a legitimate production SSO endpoint used for OAuth2 authentication and token generation.

**Impact**

Out of an abundance of caution, for organisations listed among the 140,000, it is recommended to reset Oracle LDAP and SSO passwords, updating Oracle authentication methods, and rotating any other associated credentials.

While the extent of this alleged data breach is still being clarified, it is likely that several organisations beyond the 140,000 listed could also be affected, even if they are not direct Oracle Cloud customers. Many organisations use Software as a Service (SaaS) products hosted within Oracle Cloud, which could lead to more downstream impact.

**Recommendation**

While the extent of this alleged data breach is currently unknown, it is recommended to take the following precautions if your organisation was listed.

- **Reset/Rotate Oracle Credentials:** Reset and/or rotate Oracle SSO and LDAP passwords, along with any associated credentials. Enforce strong password policies and implement Multi-Factor Authentication (MFA) to enhance security.
- **Update Oracle Authentication:** Regenerate SASL/MD5 hashes for Oracle systems or migrate to a more secure authentication method.

**References**

- CloudSEK Blog Post 1: [The Biggest Supply Chain Hack Of 2025: 6M Records Exfiltrated from Oracle Cloud affecting over 140k Tenants | CloudSEK](https://go.arcticwolf.com/ODQwLU9TUS02NjEAAAGZaORJe2ciSP1jpAe_hIslFvLAK-mtX-rKTPOL2TcZpsWt2GSGnVjpfHNzhetK_xOQ7uh5hWs=)
- CloudSEK Blog Post 2: [Part 2: Validating the Breach Oracle Cloud Denied – CloudSEK’s Follow-Up Analysis | CloudSEK](https://go.arcticwolf.com/ODQwLU9TUS02NjEAAAGZaORJe3nAJhc3qvUMAp90CN5B04I0E52O_KkHzTnRHGmTGZ4qrTghdOKqctgmPE9jLKtr_xU=)
- Bleeping Computer Article: [Oracle denies breach after hacker claims theft of 6 million data records](https://go.arcticwolf.com/ODQwLU9TUS02NjEAAAGZaORJe25r1cj5umHiYF29sTp2KEoqGY_9YEGY5yKTlA9ieKfe_iMA4SCWeNa9ridOkNXX-A8=)

 

---

Article Information Source: Artic Wolf

If you need further advice or help contact us today: [hello@coolspirit.co.uk](mailto:hello@coolspirit.co.uk)

![](https://www.coolspirit.co.uk/hubfs/website/images/curves/top/top-curve-dark-blue.svg)

## Discover our latest insights

#### Enhance your knowledge by browsing our extensive library of case studies, brief sheets, data sheets, ebooks and white papers. If you have any immediate queries or requests, why not reach out to our team?

[Explore now

](https://www.coolspirit.co.uk/insights)

###### Solutions

[![Aqua-angle](https://www.coolspirit.co.uk/hs-fs/hubfs/Aqua-angle.png?width=27&height=6&name=Aqua-angle.png)](https://www.coolspirit.co.uk/partners)

[Partners](https://www.coolspirit.co.uk/partners)  
[Hybrid Infrastructure](https://www.coolspirit.co.uk/solutions/hybrid-infrastructure)  
[Data Management](https://www.coolspirit.co.uk/solutions/data-management)  
[Networking](https://www.coolspirit.co.uk/solutions/networking)  
[Cloud](https://www.coolspirit.co.uk/solutions/cloud)  
[Cyber Security](https://www.coolspirit.co.uk/solutions/cyber-security)  
[DevOps](https://www.coolspirit.co.uk/solutions/devops)  
[GUARDiAN](https://www.coolspirit.co.uk/solutions/guardian)

###### Insights

<https://www.coolspirit.co.uk/blogs>[![Aqua-angle](https://www.coolspirit.co.uk/hs-fs/hubfs/Aqua-angle.png?width=27&height=6&name=Aqua-angle.png)](https://www.coolspirit.co.uk/partners)<https://www.coolspirit.co.uk/blogs>

[Blog](https://www.coolspirit.co.uk/blogs)  
[Case Studies](https://www.coolspirit.co.uk/case-studies)  
[Ebooks](https://www.coolspirit.co.uk/ebooks)  
[Data Sheets](https://www.coolspirit.co.uk/data-sheets)  
[Brief Sheets](https://www.coolspirit.co.uk/brief-sheets)  
[White Papers](https://www.coolspirit.co.uk/white-papers)

###### About Us

<https://www.coolspirit.co.uk/about-us/our-process>[![Aqua-angle](https://www.coolspirit.co.uk/hs-fs/hubfs/Aqua-angle.png?width=27&height=6&name=Aqua-angle.png)](https://www.coolspirit.co.uk/partners)<https://www.coolspirit.co.uk/about-us/our-process>

[Our Process](https://www.coolspirit.co.uk/about-us/our-process)  
[Accreditations](https://www.coolspirit.co.uk/accreditations)  
[Sustainability](https://www.coolspirit.co.uk/sustainability)  
[Social Responsibility](https://www.coolspirit.co.uk/social-responsibility)  
[International Shipping](https://www.coolspirit.co.uk/about/delivery-shipping)  
[Financing](https://www.coolspirit.co.uk/about/financing-plans)  
[G-Cloud 14 Framework](https://www.coolspirit.co.uk/g-cloud-14-framework)  
[News](https://www.coolspirit.co.uk/news)  
[Events](https://www.coolspirit.co.uk/events)  
[Contact](https://www.coolspirit.co.uk/contact-us)

###### Support

<https://www.coolspirit.co.uk/support/guardian-support>[![Aqua-angle](https://www.coolspirit.co.uk/hs-fs/hubfs/Aqua-angle.png?width=27&height=6&name=Aqua-angle.png)](https://www.coolspirit.co.uk/partners)<https://www.coolspirit.co.uk/support/guardian-support>

[GUARDiAN Support](https://www.coolspirit.co.uk/support/guardian-support)  
[Infrastructure Support](https://www.coolspirit.co.uk/support/infrastructure-support)

###### Get in Touch

<https://www.coolspirit.co.uk/support/guardian-support>[![Aqua-angle](https://www.coolspirit.co.uk/hs-fs/hubfs/Aqua-angle.png?width=27&height=6&name=Aqua-angle.png)](https://www.coolspirit.co.uk/partners)<https://www.coolspirit.co.uk/support/guardian-support>

T: 01246 454 222  
E: [hello@coolspirit.co.uk](mailto:hello@coolspirit.co.uk)  
Follow us: 

[Receive our newsletter

](https://www.coolspirit.co.uk/contact-us?hsLang=en)

![ISO Certifications Condensed 2025](https://www.coolspirit.co.uk/hs-fs/hubfs/ISO%20Certifications%20Condensed%202025.png?width=588&height=58&name=ISO%20Certifications%20Condensed%202025.png)

COOLSPIRiT BSI Cert. Nos: FS 550303, IS 733967, EMS 753310, ITMS 764053

Registered in England No: 3600170 All rights reserved. | Copyright © COOLSPIRiT Ltd 2024 | [Cookie Policy](https://www.coolspirit.co.uk/cookie-policy?hsLang=en) | [Privacy Policy](https://www.coolspirit.co.uk/privacy-policy?hsLang=en) | [Modern Slavery Statement](https://www.coolspirit.co.uk/modern-slavery-statement)