https://archive.ph/zFw3e

Earlier this month, a threat actor going by Rose87168 claimed to have breached Oracle Cloud’s federated SSO servers and exfiltrated around 6 million records, affecting over 144,000 Oracle clients. The hacker provided an internal customer list and threatened to sell the data unless clients paid to remove their data from the trove, which included single sign-on credentials, Lightweight Directory Access Protocol passwords, OAuth2 keys, tenant data, and more. Rose87168 has also solicited help from the hacking community to crack the hashed password in trade for some of the data.

  • AlecSadler@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 day ago

    Maybe in some cases. This particular company at the time had revenue of $5M, with a much lower net, so $2M want even feasible.

    • AnUnusualRelic@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      20 hours ago

      They’re probably not a very good candidate to be an Oracle client either. They typically target larger accounts. Shame to end up stuck like that.