ZeroFox Intelligence Flash Report - Situation Report: Alleged Oracle Breach
|by Alpha Team

ZeroFox Intelligence Flash Report - Situation Report: Alleged Oracle Breach
Product Serial: F-2025-03-26a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the recently-alleged compromise of U.S.-based technology firm Oracle, in the deep web forum BreachForums.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- As of this writing, stolen data allegedly associated with U.S.-based technology firm Oracle has not been shared in its entirety or sold to any known actor or entity, and although some alleged victims have confirmed the data is legitimate, investigations are ongoing.
- On March 20, 2025, actor “rose87168” posted in the predominantly Russian-speaking forum BreachForums, claiming to have stolen data associated with six million users of Oracle Cloud services.
- Rose87168 did not disclose the asking price of the full dataset, instead urging prospective buyers to make contact. The actor further specified that organizations can pay "a specific amount" to have their data deleted before it is sold.
- The data’s utility in conducting subsequent exploitative activity—such as the further compromise of downstream and adjacent Oracle services or accessing sensitive and proprietary information held within workspaces—is heavily dependent on individual use and security configuration.
- There is a very likely chance that the threat posed to alleged victims will be lessened by the time any purchase takes place, as organizations enact precautionary security procedures to mitigate the impact of subsequent exploitation.
Tags: global, us/canada, tlp:clear, data breach, threat actor