HomeNewsOracle beneath hearth for its dealing with of separate security incidents

Oracle beneath hearth for its dealing with of separate security incidents

Tech large Oracle is going through criticism for the way it’s dealing with two seemingly separate data breaches. 

No less than one of many incidents seems to nonetheless be unfolding, regardless of Oracle reportedly denying a breach in any respect. The opposite pertains to a breach of affected person information beneath the tech large’s healthcare subsidiary, Oracle Well being.

Oracle didn’t reply to information.killnetswitch’s request for remark in regards to the two incidents.

Oracle Well being breach impacts affected person information, per studies

The breach disclosed most lately entails Oracle Well being, which offers hospitals and different healthcare suppliers with know-how to entry well being data on-line. Oracle Well being is a unit that was mixed with Cerner, an digital well being data firm that Oracle acquired in 2022 for $28 billion.

Bloomberg and Bleeping Laptop reported final week that the breach impacts affected person information, though it’s unclear precisely what sorts of information have been stolen, nor which organizations and corporations that use Oracle Well being are affected. 

Oracle notified a few of its healthcare clients in March of a breach that occurred someday earlier this 12 months, through which hackers accessed Oracle servers and stole affected person information, in line with the publications.

See also  5 frequent information security pitfalls — and how one can keep away from them

Contact Us

Do you’ve gotten extra details about these two Oracle breaches? From a non-work system and community, you’ll be able to contact Lorenzo Franceschi-Bicchierai securely on Sign at +1 917 257 1382, or through Telegram and Keybase @lorenzofb, or e-mail. You can also contact information.killnetswitch through SecureDrop.

“We’re writing to tell you that, on or round February 20, 2025, we grew to become conscious of a cybersecurity occasion involving unauthorized entry to some quantity of your Cerner information that was on an previous legacy server not but migrated to the Oracle Cloud,” learn the notification despatched to some Oracle Well being clients, in line with Bleeping Laptop. 

Citing a number of sources, the information website reported {that a} hacker is attempting to extort affected hospitals, reportedly demanding hundreds of thousands of {dollars}. 

An Oracle worker, who requested to stay nameless, as they weren’t licensed to talk to the press, informed information.killnetswitch that the corporate hasn’t been very clear even with its personal workers. 

“My staff was not in a position to entry clients’ environments for quite a few days. My concern isn’t just with affected person data breach. Entry by means of hosts permits any and all entry to what’s hosted, clearly,” stated the worker. “Some clients host different functions like HR and finance. I don’t know if it was hacker[-]accessed although.”

See also  Cybersecurity startups to observe for in 2023

The worker stated they’d to take a look at Reddit and inner Slack channels “to even determine one thing was being checked out.”

The worker stated they “felt tremendous ignored,” describing the scenario as: “Nothing to see right here, transfer proper alongside.”

The worker, nevertheless, additionally stated that they noticed on Slack that some groups got language to speak with shoppers on March 4: “We are going to examine the problem you might be experiencing.”

Oracle denies cloud breach, regardless of mounting proof

The opposite separate breach entails Oracle Cloud servers. And on this case, too, Oracle isn’t being very clear about what occurred. 

Earlier this month, a hacker going by the net deal with rose87168 posted on a cybercrime discussion board providing the info of 6 million Oracle Cloud clients, together with authentication information and encrypted passwords, as Bleeping Laptop reported on the time. 

To show that they breached Oracle, rose87168 uploaded a textual content file containing their on-line deal with that was hosted on an Oracle Cloud server.

A screenshot of the archived textual content file that rose87168 uploaded to an Oracle server. Picture Credit:information.killnetswitch (screenshot)

Since, a number of Oracle clients have confirmed that information samples shared by the hacker seem real, pointing to additional proof of a breach at Oracle.

See also  Bitbucket integrates Arnica’s utility security instruments

Unusually, Oracle denied that there was a breach in any respect. 

“There was no breach of Oracle Cloud. The printed credentials usually are not for the Oracle Cloud. No Oracle Cloud clients skilled a breach or misplaced any information,” Oracle informed the publication.

However not everyone seems to be satisfied. 

“This can be a severe cybersecurity incident which impacts clients, in a platform managed by Oracle,” cybersecurity skilled Kevin Beaumont wrote in a weblog publish analyzing the alleged Oracle Cloud breach. “Oracle try to wordsmith statements round Oracle Cloud and use very particular phrases to keep away from accountability. This isn’t okay.” 

“Oracle want to obviously, brazenly and publicly talk what occurred, the way it impacts clients, and what they’re doing about it. This can be a matter of belief and accountability. Step up, Oracle — or clients ought to begin stepping off,” stated Beaumont.

Commenting on one of many alleged Oracle breaches, cybersecurity skilled Lisa Forte wrote on Bluesky that “if this finally ends up being true, and I wrestle to see the way it gained’t, it is a very very dangerous look.”

- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular