Live data from Hacker News

Oracle customers confirm data stolen in alleged cloud breach is valid

bleepingcomputer.com

11–20 of 85 posts

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#11
post #6

Alone the fact that Oracle was hosting their login gateway on a product with a known vulnerability from 2021 with a CVSS score of 9.8 is quite disturbing.

Fun fact: Oracle has like 6+ LDAP/directory products, OAM is just one. Theres ODS, OIM, OID, OUD, OVD, NIS leftovers from Sun, and probably more honestly

And you can't just use your AD, you have to install OID and have it synchronized.

It just makes me mad.

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#12
post #10
post #8

Earlier quoted context omitted.

> It's not like there are any real penalties to a breach. Not in the US maybe. In the EU under GDPR you have to disclose within 48h of you realizing (or made aware of) the breach. There are fines (at least) if you don't disclose it afaik. Oracle is gonna have issue with the EU, most likely.

Have their been any GDPR fines that amount to more than a rounding error of Oracle's revenue? Admittedly, I don't watch too closely, but from the ones I am aware of, I haven't seen any GDPR fines that made me finally think "wow, that might actually count as a punishment". (I would honestly be happy to learn of some!) There are disclosure laws in the US as well, but again, the fines are like a days worth of revenue. M…

Several of the fines have been in the hundreds of millions of dollars - and while not crushing to Oracle, that's actual money that will definitely change behavior.. https://www.enforcementtracker.com/

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#14
post #10

Earlier quoted context omitted.

Have their been any GDPR fines that amount to more than a rounding error of Oracle's revenue? Admittedly, I don't watch too closely, but from the ones I am aware of, I haven't seen any GDPR fines that made me finally think "wow, that might actually count as a punishment". (I would honestly be happy to learn of some!) There are disclosure laws in the US as well, but again, the fines are like a days worth of revenue. M…

Several of the fines have been in the hundreds of millions of dollars - and while not crushing to Oracle, that's actual money that will definitely change behavior.. https://www.enforcementtracker.com/

Nice, thanks for the link!

The largest fine ever issued is about 2% of Oracle's 2024 revenue. If we average the top 5 fines ever issued (this breach surely wont result in the largest GDPR fine ever), it'd be about 1% of Oracle's 2024 revenue. So, between ~3.5 and ~7 days worth of revenue, if we're lucky and get a top 5 GDPR fine?

I'm not sure that is in the "definitely change behavior" area yet (in fact, I'm confident it is not), but better than I thought.

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#15

Earlier quoted context omitted.

It appears they took dogfooding a little too literally

Ironically, they didn’t see this coming.

To be fair, the vulnerability is only 4 years old. There is no way they could have noticed it, let alone resolved it that quickly.

This is Oracle.

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#16

Alone the fact that Oracle was hosting their login gateway on a product with a known vulnerability from 2021 with a CVSS score of 9.8 is quite disturbing.

we pay millions to Oracle. We hit a bug and it took 6months for them to reproduce and acknowledge there is a bug. they now seem to be on the lookout for someone being able to produce a fix: sales and indian after-sales can't do that... curious!

Oracle seems just a moneygrabbing shell company at this point and I suppose the whole hyperscaler-cloud is developing towards that point with the leaders of those corporations repeating exactly the same talking points...

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#18
post #10
post #8

Earlier quoted context omitted.

> It's not like there are any real penalties to a breach. Not in the US maybe. In the EU under GDPR you have to disclose within 48h of you realizing (or made aware of) the breach. There are fines (at least) if you don't disclose it afaik. Oracle is gonna have issue with the EU, most likely.

Have their been any GDPR fines that amount to more than a rounding error of Oracle's revenue? Admittedly, I don't watch too closely, but from the ones I am aware of, I haven't seen any GDPR fines that made me finally think "wow, that might actually count as a punishment". (I would honestly be happy to learn of some!) There are disclosure laws in the US as well, but again, the fines are like a days worth of revenue. M…

In the UK, and I presume the EU also, the fines for losing customer data are set as a % of company annual worldwide turnover.

https://ico.org.uk/for-organisations/law-enforcement/guide-t...

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#19
post #10

Earlier quoted context omitted.

Have their been any GDPR fines that amount to more than a rounding error of Oracle's revenue? Admittedly, I don't watch too closely, but from the ones I am aware of, I haven't seen any GDPR fines that made me finally think "wow, that might actually count as a punishment". (I would honestly be happy to learn of some!) There are disclosure laws in the US as well, but again, the fines are like a days worth of revenue. M…

In the UK, and I presume the EU also, the fines for losing customer data are set as a % of company annual worldwide turnover. https://ico.org.uk/for-organisations/law-enforcement/guide-t...

According to the GDPR enforcement tracker link helpfully provided by the sibling commenter, we'll be lucky to see a ~1% fine of the 2024 revenue of Oracle. That's assuming that the fine issued is in the top 5 GDPR fines ever issued. Even 4%, the cited higher maximum on your link, is kind of peanuts (not sure this breach would even qualify for the "higher maximum", as I'm unfamiliar with the laws, so it could be a maximum of 2% if counted as a "standard maximum").

To me, that's still in the "cost of doing business" territory, not the "punishment" territory.

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#20
post #8
post #7

> BleepingComputer has confirmed with multiple companies that associated data samples shared by the threat actor are valid. > In addition to the data, rose87168 shared an Archive.org URL with BleepingComputer for a text file hosted on the "login.us2.oraclecloud.com" server that contained their email address. This file indicates that the threat actor could create files on Oracle's server, indicating an actual breach.…

> It's not like there are any real penalties to a breach. Not in the US maybe. In the EU under GDPR you have to disclose within 48h of you realizing (or made aware of) the breach. There are fines (at least) if you don't disclose it afaik. Oracle is gonna have issue with the EU, most likely.

SEC Fact Sheet: Public Company Cybersecurity Disclosures; Final Rules - https://www.sec.gov/files/33-11216-fact-sheet.pdf
Post reply on HN