Oracle customers confirm data stolen in alleged cloud breach is valid
bleepingcomputer.com
Oracle customers confirm data stolen in alleged cloud breach is valid
1–10 of 85 posts
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#2Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#3Alone the fact that Oracle was hosting their login gateway on a product with a known vulnerability from 2021 with a CVSS score of 9.8 is quite disturbing.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#4Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#5Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#6Alone the fact that Oracle was hosting their login gateway on a product with a known vulnerability from 2021 with a CVSS score of 9.8 is quite disturbing.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#7>In addition to the data, rose87168 shared an Archive.org URL with BleepingComputer for a text file hosted on the "login.us2.oraclecloud.com" server that contained their email address. This file indicates that the threat actor could create files on Oracle's server, indicating an actual breach.
Oracle probably should have just admitted the validity up front.
It's not like there are any real penalties to a breach. Lying about it is probably a worse PR hit than the breach itself.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#8> BleepingComputer has confirmed with multiple companies that associated data samples shared by the threat actor are valid. > In addition to the data, rose87168 shared an Archive.org URL with BleepingComputer for a text file hosted on the "login.us2.oraclecloud.com" server that contained their email address. This file indicates that the threat actor could create files on Oracle's server, indicating an actual breach.…
Not in the US maybe. In the EU under GDPR you have to disclose within 48h of you realizing (or made aware of) the breach.
There are fines (at least) if you don't disclose it afaik.
Oracle is gonna have issue with the EU, most likely.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#9Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#10> BleepingComputer has confirmed with multiple companies that associated data samples shared by the threat actor are valid. > In addition to the data, rose87168 shared an Archive.org URL with BleepingComputer for a text file hosted on the "login.us2.oraclecloud.com" server that contained their email address. This file indicates that the threat actor could create files on Oracle's server, indicating an actual breach.…
> It's not like there are any real penalties to a breach. Not in the US maybe. In the EU under GDPR you have to disclose within 48h of you realizing (or made aware of) the breach. There are fines (at least) if you don't disclose it afaik. Oracle is gonna have issue with the EU, most likely.
There are disclosure laws in the US as well, but again, the fines are like a days worth of revenue. Maybe the breached company has to provide a year of credit monitoring for the affected persons, if lucky.