Back in September 2019, Oracle announced a free tier in their Oracle Cloud. Terms were pretty generous (two 1GB VMs, 100GB disk, 10TB transfer) and this option was very popular in our community.
Unfortunately, today CloudSEK announced that 140K tenants’ data (6 million records) have been leaked.
On 21 March 2025, CloudSEK’s XVigil discovered a threat actor, “rose87168,” selling 6M records exfiltrated from SSO and LDAP of Oracle Cloud. The data includes JKS files, encrypted SSO passwords, key files, and enterprise manager JPS keys.
The attacker, active since January 2025, is incentivizing decryption assistance and demanding payment for data removal from over 140K affected tenants. Our engagement with the threat actor suggests a possible undisclosed vulnerability on login.(region-name).oraclecloud.com, leading to unauthorized access. While the threat actor has no prior history, their methods indicate high sophistication, CloudSEK assesses this threat with medium confidence and rates it as High in severity.
According to the hacker, Tesla, Nike, Adidas, Visa, and other firms are affected. It’s not clear if the free tier is affected. The hack refers to SSO, LDAP, and other functions that are more typically used by large enterprises.
There is a page where you can check your check your exposure.
Update: LowEndTalk member @dedipromo confirmed that the free tier is affected, too.
Related Posts:
MariaDB Swallowed by Private Equity
Google is Building a Datacenter in...um, Where...?!?
Oracle Cloud Launches in Colombia, While AWS/GCP/Azure Lag in South America
CLONE WARS: How Every Major RHEL Clone is Reacting to IBM, From Counter-Exploiting Legal Loopholes t...
From Oracle Cloud to TOR to Telegram: Check Out LowEndTalk Tutorials!
PostgreSQL 15 is Released!
- I’ve Got a Big Crush on the Little PicoCalc From clockworkPi!Lots Cheaper Than a Boring Calculator and Tons More Power! - March 27, 2025
- Cheap Dedicated Server! eWallHost has $39/Month Dedis in the Netherlands! - March 26, 2025
- netcup Deal Day: 16 Hours Left to Get Beefy Servers With Tons of Disk! - March 25, 2025
Leave a Reply