Oracle Reports Second Cybersecurity Breach; Legacy Customer Credentials Stolen
Oracle has alerted its clients to a second cybersecurity breach where legacy customer log-in credentials were stolen, with some data dated as recent as 2024. The FBI and CrowdStrike are currently investigating the incident.
Published on April 3, 2025
Oracle informed its clients on April 2, 2025, that a second cybersecurity breach had occurred, resulting in the theft of old customer log‐in credentials from a legacy system that has been offline for eight years. According to the report, some of the compromised data—even as recent as 2024—has been offered for sale online. The company stressed that the breach is unrelated to a previous hack affecting healthcare clients, and authorities, including the FBI and cybersecurity firm CrowdStrike, are investigating the incident.
While Oracle has not yet made a public comment, details from supplemental research reinforce that the hacker allegedly attempted to extort the company. The investigation remains ongoing, with inquiries being referred back to Oracle for further information. Additional reports from reputable sources provide context on Oracle’s broader cybersecurity challenges during this period.