While Oracle has not officially confirmed the breach, researchers believe the attacker exploited either a zero-day vulnerability or a misconfiguration in the OAuth2 authentication layer, granting unauthorized access to highly sensitive information such as single sign on (SSO) credentials, LDAP passwords, OAuth keys, and tenant-specific data.
Cloud-AI-Cybercrime-Solution-BriefThe Oracle Cloud Breach Exposed a Harsh Truth: Public Cloud Infrastructure Is a Growing AI Attack Surface For Cybercriminals
In early 2025, a threat actor known as Rose87168 claimed responsibility for a major breach of Oracle Cloud Infrastructure, allegedly compromising over 6 million records across 140,000 tenants.