LowEndBox - Cheap VPS, Hosting and Dedicated Server Deals

"The Biggest Supply Chain Hack of 2025": Oracle Cloud Leaks 140K Tenants' Details

Oracle CloudBack in September 2019, Oracle announced a free tier in their Oracle Cloud.  Terms were pretty generous (two 1GB VMs, 100GB disk, 10TB transfer) and this option was very popular in our community.

Unfortunately, today CloudSEK announced that 140K tenants’ data (6 million records) have been leaked.

On 21 March 2025, CloudSEK’s XVigil discovered a threat actor, “rose87168,” selling 6M records exfiltrated from SSO and LDAP of Oracle Cloud. The data includes JKS files, encrypted SSO passwords, key files, and enterprise manager JPS keys.

The attacker, active since January 2025, is incentivizing decryption assistance and demanding payment for data removal from over 140K affected tenants. Our engagement with the threat actor suggests a possible undisclosed vulnerability on login.(region-name).oraclecloud.com, leading to unauthorized access. While the threat actor has no prior history, their methods indicate high sophistication, CloudSEK assesses this threat with medium confidence and rates it as High in severity.

According to the hacker, Tesla, Nike, Adidas, Visa, and other firms are affected.  It’s not clear if the free tier is affected.  The hack refers to SSO, LDAP, and other functions that are more typically used by large enterprises.

There is a page where you can check your check your exposure.

Update: LowEndTalk member @dedipromo confirmed that the free tier is affected, too.

raindog308

No Comments

    Leave a Reply

    Some notes on commenting on LowEndBox:

    • Do not use LowEndBox for support issues. Go to your hosting provider and issue a ticket there. Coming here saying "my VPS is down, what do I do?!" will only have your comments removed.
    • Akismet is used for spam detection. Some comments may be held temporarily for manual approval.
    • Use <pre>...</pre> to quote the output from your terminal/console, or consider using a pastebin service.

    Your email address will not be published. Required fields are marked *