https://archive.ph/zFw3e

Earlier this month, a threat actor going by Rose87168 claimed to have breached Oracle Cloud’s federated SSO servers and exfiltrated around 6 million records, affecting over 144,000 Oracle clients. The hacker provided an internal customer list and threatened to sell the data unless clients paid to remove their data from the trove, which included single sign-on credentials, Lightweight Directory Access Protocol passwords, OAuth2 keys, tenant data, and more. Rose87168 has also solicited help from the hacking community to crack the hashed password in trade for some of the data.

  • TedDallas@programming.dev
    link
    fedilink
    English
    arrow-up
    50
    ·
    2 days ago

    Oracle is a public company. Public companies must file data breaches with the SEC or they can get into some hot water. They are not ran by smart people.

    • Phoenixz@lemmy.ca
      link
      fedilink
      English
      arrow-up
      12
      ·
      1 day ago

      You mean the SEC in the US? You’re kidding right? Nobody cares about any of that anymore. Does the SEC even still exist? Worst case scenario, Oracle just gives some money to Cheeto and they’re done

      • TedDallas@programming.dev
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 hours ago

        Yes. It exists. Whether or not they are actively enforcing anything during the current administration is open to question. The fortune 10 company I work for takes the SEC seriously.

  • Mora@pawb.social
    link
    fedilink
    English
    arrow-up
    50
    ·
    2 days ago

    I hope Oracle will finally send out mails to the affected customers. No idea if I am affected as Oracles login process is so convoluted that I have no desire to deal with it or understand it.

  • Elvith Ma'for@feddit.org
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 days ago

    Ok, who of you guys is working with Oracle Cloud and has not yet rerolled all API/Access Keys, passwords and so on? And what company do you happen work for? ^Just asking for a friend^

    • derpgon@programming.dev
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 hours ago

      I wonder how many of those companies - that are stuck with Oracle due to legacy software - have just too many keys to reroll that they just won’t do it. Mainly due to everything being a manual process.

      • Elvith Ma'for@feddit.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        39 minutes ago

        At least we’re constantly told to be ready to act to reroll secrets, etc and try to automate the change/deployment of changed passwords and such.

        Depending on the system you’re working with, this may still be a PITA, but at least we do have plans for even the “problematic” systems and we have probably done this a few times. Although maybe not at this scale, tbh.

        So, imagining I were tasked to do that for $hyperscaler in “my” systems… I feel some dread, as even if everything is automated ä, there’s always something that doesn’t go as planned - but at least I know what can be done in which way and which timeframe is realistic (and which parts will be the most sensitive). If you do not have plans, well… Good luck. You’ll need it.