Live data from Hacker News

Oracle customers confirm data stolen in alleged cloud breach is valid

bleepingcomputer.com

21–30 of 85 posts

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#22
post #19

Earlier quoted context omitted.

In the UK, and I presume the EU also, the fines for losing customer data are set as a % of company annual worldwide turnover. https://ico.org.uk/for-organisations/law-enforcement/guide-t...

According to the GDPR enforcement tracker link helpfully provided by the sibling commenter, we'll be lucky to see a ~1% fine of the 2024 revenue of Oracle. That's assuming that the fine issued is in the top 5 GDPR fines ever issued. Even 4%, the cited higher maximum on your link, is kind of peanuts (not sure this breach would even qualify for the "higher maximum", as I'm unfamiliar with the laws, so it could be a max…

4% of revenue is terrifying for large corporations.

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#23
> In this email exchange, the threat actor says someone from Oracle using a @proton.me email address told them that "We received your emails. Let’s use this email for all communications from now on. Let me know when you get this."

E-mails are one of the sources at most public companies that are required to retain for a period of time (7 yrs?). Probably trying to avoid a paper trail?

Data breaches, unfortunately, have no impact to stock. Companies that use Oracle products are unlikely to migrate any time soon.

_future_ sales may be impacted and maybe some smaller players can migrate off. But Oracle will downplay it as much as possible.

“Deny. Delay. Defend.” Is not just a health insurance slogan.

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#24
post #10

Earlier quoted context omitted.

Have their been any GDPR fines that amount to more than a rounding error of Oracle's revenue? Admittedly, I don't watch too closely, but from the ones I am aware of, I haven't seen any GDPR fines that made me finally think "wow, that might actually count as a punishment". (I would honestly be happy to learn of some!) There are disclosure laws in the US as well, but again, the fines are like a days worth of revenue. M…

In the UK, and I presume the EU also, the fines for losing customer data are set as a % of company annual worldwide turnover. https://ico.org.uk/for-organisations/law-enforcement/guide-t...

If a fine isn't an existential threat what's the point of it? Hoping next time they'll care more? tf?

the EU needs to tack another 0 to these percentages if they want to see movement.

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#25
post #19

Earlier quoted context omitted.

According to the GDPR enforcement tracker link helpfully provided by the sibling commenter, we'll be lucky to see a ~1% fine of the 2024 revenue of Oracle. That's assuming that the fine issued is in the top 5 GDPR fines ever issued. Even 4%, the cited higher maximum on your link, is kind of peanuts (not sure this breach would even qualify for the "higher maximum", as I'm unfamiliar with the laws, so it could be a max…

4% of revenue is terrifying for large corporations.

It's impossible to take their fears seriously—literally any kind of social obligation is going to be scary for an entity with no desire to do anything but feed its owners.

Wait until you see what kind of reaction 40% gets! Existential threats will be the only things that work.

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#26
post #19

Earlier quoted context omitted.

According to the GDPR enforcement tracker link helpfully provided by the sibling commenter, we'll be lucky to see a ~1% fine of the 2024 revenue of Oracle. That's assuming that the fine issued is in the top 5 GDPR fines ever issued. Even 4%, the cited higher maximum on your link, is kind of peanuts (not sure this breach would even qualify for the "higher maximum", as I'm unfamiliar with the laws, so it could be a max…

4% of revenue is terrifying for large corporations.

Have they ever issued a fine for 4% of revenue? That's the maximum fine possible, under the non-standard "higher maximum" category. This breach surely won't be given the maximum considering there isn't really anything noteworthy about it.

We should consider the maximum that has actually been issued, than subtract some off of that. You also have to subtract out all of the money they saved over the years of reduced investment into security.

I think that lands us squarely back into "cost of doing business" land.

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#27
post #14

Earlier quoted context omitted.

Several of the fines have been in the hundreds of millions of dollars - and while not crushing to Oracle, that's actual money that will definitely change behavior.. https://www.enforcementtracker.com/

Nice, thanks for the link! The largest fine ever issued is about 2% of Oracle's 2024 revenue. If we average the top 5 fines ever issued (this breach surely wont result in the largest GDPR fine ever), it'd be about 1% of Oracle's 2024 revenue. So, between ~3.5 and ~7 days worth of revenue, if we're lucky and get a top 5 GDPR fine? I'm not sure that is in the "definitely change behavior" area yet (in fact, I'm confiden…

7 days of revenue, 1 whole week out of 52 that all of your workforce production went to pay a fine? Yeah, that's quite noticeable for a corporation.

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#28
post #27
post #14

Earlier quoted context omitted.

Nice, thanks for the link! The largest fine ever issued is about 2% of Oracle's 2024 revenue. If we average the top 5 fines ever issued (this breach surely wont result in the largest GDPR fine ever), it'd be about 1% of Oracle's 2024 revenue. So, between ~3.5 and ~7 days worth of revenue, if we're lucky and get a top 5 GDPR fine? I'm not sure that is in the "definitely change behavior" area yet (in fact, I'm confiden…

7 days of revenue, 1 whole week out of 52 that all of your workforce production went to pay a fine? Yeah, that's quite noticeable for a corporation.

If this breach receives a fine in the top 5 fines ever issued in the entire history of GDPR enforcement.

Don't forget to subtract out the money they saved from reduced investment in security over that time, as well.

Noticeable? Sure. Nowhere near noticeable enough, though, in my opinion. Especially if we're serious about it and recognize this isn't going to be a top 5 fine.

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#29
post #16

Alone the fact that Oracle was hosting their login gateway on a product with a known vulnerability from 2021 with a CVSS score of 9.8 is quite disturbing.

we pay millions to Oracle. We hit a bug and it took 6months for them to reproduce and acknowledge there is a bug. they now seem to be on the lookout for someone being able to produce a fix: sales and indian after-sales can't do that... curious! Oracle seems just a moneygrabbing shell company at this point and I suppose the whole hyperscaler-cloud is developing towards that point with the leaders of those corporations…

Why are you still on Oracle? (genuine question, no snark)

Re: Oracle customers confirm data stolen in alleged cloud breach is valid

#30
Okay having worked at a top 3 insurance broker about 10 years ago when “Cyber” policies were being rolled out (h/t Beasley)…I wonder who underwrote Oracle’s policy and how much it was in that tower? No policy? Hope the D&O can cover the shareholder lawsuits! Wait, something something cozy with administration in power, rules subject to interpretation, etc.

Then again, Tyler Technologies blamed Judyrecords.com for their exposing reams of sealed cases in California because of their flawed obfuscation system and claimed it was a security breach (somehow skated on accountability there).

Rule #1 of a breach is never write the word breach in an email, hence the discussion off their dot com I figure…

Post reply on HN