INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Oracle Health/Cerner Data Breach Affects Almost 20 Million Individuals
| 2026-10-08 07:12 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A 2025 data breach involving electronic protected health information stored on Oracle Health's legacy Cerner servers has affected almost 20 million individuals, with the Texas Attorney General reporting that nearly 2.99 million individuals were impacted in Texas alone. The breach was identified by Oracle Health on March 7, 2025, and is believed to have been caused by a solitary hacker who demanded a ransom payment from Oracle Health. The data compromised included names, Social Security numbers, medical record-related health information, and diagnoses, care and treatment information, medications, test results, medical images, and physician names. As of October 2, 2026, the Texas Attorney General had been provided with an updated total number of affected individuals, but this figure has yet to be reflected on the HHS' Office for Civil Rights breach portal, which currently lists a placeholder total of 501 individuals.
Technical Mitigations AI-generated
• Migrate legacy Cerner servers to Oracle Cloud as soon as possible.
• Implement robust security due diligence during mergers and acquisitions, including thorough vulnerability assessments of acquired companies' systems.
• Regularly review and update system access controls for all employees with elevated privileges.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2021-35587CVE-2021-35587
Target & Sectors
Global Scope
legallegal
healthhealth
Incident Timeline
December 2021
Oracle announced an agreement to buy Cerner Corporation in December 2021.
June 2022
Threat actors exploited a previously unknown vulnerability in the merged Oracle Health/Cerner system to compromise sensitive data of nearly 20 million individuals.
January 2025
A class action lawsuit has been filed against Oracle Corporation on behalf of individuals whose personal data was compromised in a January 2025 data breach.
Click on any entity below to view its context and source!
tactic
Data Breach
April 3, 2025: Oracle Sued Over Healthcare Data Breach
A class action lawsuit has been filed against Oracle Corporation by a Florida resident in the U.S. District Court for the Western District of Texas over a January 2025 data breach.
organisation
Healthcare Data Breach
April 3, 2025: Oracle Sued Over Healthcare Data Breach
A class action lawsuit has been filed against Oracle Corporation by a Florida resident in the U.S. District Court for the Western District of Texas over a January 2025 data breach.
organisation
Oracle Corporation
April 3, 2025: Oracle Sued Over Healthcare Data Breach
A class action lawsuit has been filed against Oracle Corporation by a Florida resident in the U.S. District Court for the Western District of Texas over a January 2025 data breach.
organisation
the Department of Health and Human Services
Oracle has yet to publicly confirm that there has been a data breach, and the incident has yet to appear on the breach portal of the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), so it is currently unclear how many individuals have been affected.
organisation
HHS) Office for Civil Rights
Oracle has yet to publicly confirm that there has been a data breach, and the incident has yet to appear on the breach portal of the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), so it is currently unclear how many individuals have been affected.
organisation
Shamis & Gentile
The lawsuit, filed by the law firm Shamis & Gentile, names Michael Toikach as plaintiff and was filed on behalf of other similarly situated individuals who had their personal data compromised in the incident.
January 22, 2025
Threat actors allegedly exploited a vulnerability in Oracle Access Manager (CVE-2021-35587) to access and exfiltrate sensitive data from over 140,000 customers using Oracle Cloud services.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
organisation
the U.S. Department of Health and Human Services
Under the HIPAA Breach Notification Rule, in the event of a breach of unsecured protected health information, the U.S. Department of Health and Human Services must be notified about a data breach without undue delay and no later than 60 days from the date of discovery of the data breach.
organisation
CVE-2021-35587
The vulnerability she allegedly exploited was CVE-2021-35587 and affects Oracle Access Manager.
organisation
Oracle Access
The vulnerability she allegedly exploited was CVE-2021-35587 and affects Oracle Access Manager.
organisation
the Health Insurance Portability
The types of data involved are unclear but appear to include data contained in electronic health records, which would make it a reportable breach under the Health Insurance Portability and Accountability Act (HIPAA).
organisation
Oracle Health’s Chief Information Security Office
The Oracle Health notification letters were reportedly signed by Seema Verma, Executive Vice President & GM of Oracle Health; however, the letters were not sent on headed paper, and the affected customers have been told to contact Oracle Health’s Chief Information Security Office (CISO) directly over the phone, not via email.
organisation
Oracle Cloud
In what appears to be a separate incident, another individual claims to have exploited a vulnerability around a month ago and accessed an Oracle Cloud server and exfiltrated approximately 6 million records.
data_breach
6 records
In what appears to be a separate incident, another individual claims to have exploited a vulnerability around a month ago and accessed an Oracle Cloud server and exfiltrated approximately 6 million records.
organisation
rose87168
A person using the name rose87168 said she obtained SSO authentication data and encrypted LDAP passwords, which she claims could be decrypted using information in the stolen files.
organisation
SSO
A person using the name rose87168 said she obtained SSO authentication data and encrypted LDAP passwords, which she claims could be decrypted using information in the stolen files.
organisation
CloudSEK
CloudSEK researchers reviewed the data provided by rose87168 and concluded with medium confidence that it rates high in severity and involved more than 140,000 customers who use Oracle Cloud services.
victims
140,000 customers
CloudSEK researchers reviewed the data provided by rose87168 and concluded with medium confidence that it rates high in severity and involved more than 140,000 customers who use Oracle Cloud services.
around January 22, 2025
Threat actors used stolen credentials to access Oracle Health/Cerner servers on or around January 22, 2025.
February 20, 2025
The two named plaintiffs claim Oracle Health failed to issue timely breach notifications, violating both the HIPAA Breach Notification Rule and a Texas data breach notification statute.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
organisation
the HIPAA Breach Notification Rule
The lawsuit takes issue with the lack of notifications, which under the HIPAA Breach Notification Rule should be issued without undue delay and no later than 60 days from the date the data breach was discovered.
organisation
the U.S.
This lawsuit was filed in the U.S. District Court for the Western District of Missouri and claims a hacker stole sensitive information, including names, Social Security numbers, clinical test results, and other protected health information.
organisation
District Court
This lawsuit was filed in the U.S. District Court for the Western District of Missouri and claims a hacker stole sensitive information, including names, Social Security numbers, clinical test results, and other protected health information.
organisation
Cerner
The lawsuit claims Oracle Health was negligent by failing to secure servers after the $28.3 billion acquisition of Cerner in 2022.
financial
$28.3 acquisition
The lawsuit claims Oracle Health was negligent by failing to secure servers after the $28.3 billion acquisition of Cerner in 2022.
organisation
HIPAA
Oracle Health explained in its notifications to its healthcare provider customers that it is their responsibility to determine if a breach occurred that is reportable under HIPAA, and also their responsibility to issue breach notifications to the affected individuals if they determine a reportable breach occurred.
March 7, 2025
Threat actors exploited a vulnerability in Oracle Health/Cerner's systems to breach sensitive data, affecting nearly 20 million individuals.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
March 2025
Threat actors exploited unsecured legacy systems at Cerner Corporation, which was acquired by Oracle in 2022 and subsequently merged into Oracle Health, to steal data that would be published unless a ransom payment is made.
Click on any entity below to view its context and source!
organisation
Cerner Corporation
Oracle acquired Cerner Corporation in 2022 in a $28.4 billion deal, and merged the company into Oracle Health.
financial
$28.4 deal
Oracle acquired Cerner Corporation in 2022 in a $28.4 billion deal, and merged the company into Oracle Health.
organisation
Owner
I don’t like the fact that Oracle is kind of hand-waving this away by saying these were legacy systems that hadn’t been migrated to their secure cloud services yet,” John Strand, Owner, Black Hills Information Security Inc., told the HIPAA Journal.
organisation
Black Hills Information Security Inc.
I don’t like the fact that Oracle is kind of hand-waving this away by saying these were legacy systems that hadn’t been migrated to their secure cloud services yet,” John Strand, Owner, Black Hills Information Security Inc., told the HIPAA Journal.
organisation
the HIPAA Journal
I don’t like the fact that Oracle is kind of hand-waving this away by saying these were legacy systems that hadn’t been migrated to their secure cloud services yet,” John Strand, Owner, Black Hills Information Security Inc., told the HIPAA Journal.
March 31, 2025
Threat actors exploited a vulnerability in Oracle Health's systems to access and potentially exfiltrate sensitive patient data related to Cerner's electronic health records.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
organisation
EHR
Oracle Health Breach Affects Patients of Multiple U.S. Hospitals
Oracle appears to have suffered two security incidents, one of which involved data stored by Oracle Health related to the electronic health record (EHR) company Cerner.
April 1, 2025
A solitary hacker exploited vulnerabilities to breach Oracle Health/Cerner's systems between January 22, 2025, and April 1, 2025.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
organisation
Social Security
Data compromised in the incident included names, Social Security numbers, and medical record-related health information, including diagnoses, care and treatment information, medications, test results, medical images, medical record numbers, and physician names.
April 3, 2025
Threat actors used a sophisticated attack vector to breach the combined health records of Oracle Health and Cerner, compromising data from nearly 20 million individuals.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
April 7, 2025
Threat actors, claiming to be rose87168 and Andrew, are attempting to sell stolen data records from Oracle Health's Gen1 cloud services.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
organisation
Oracle Cloud Infrastructure
Oracle explained in its April 7, 2025, email notification to customers that “Oracle would like to state unequivocally that the Oracle Cloud – Also known as Oracle Cloud Infrastructure or OCI – has not experienced a security breach.”
organisation
OCI
Oracle explained in its April 7, 2025, email notification to customers that “Oracle would like to state unequivocally that the Oracle Cloud – Also known as Oracle Cloud Infrastructure or OCI – has not experienced a security breach.”
organisation
Gen1
According to security researcher Kevin Beaumont, the “obsolete servers” were Gen1, aka Oracle Cloud Classic, a different platform from Oracle Cloud, but they were Oracle-managed cloud services.
organisation
The Oracle Health
The Oracle Health incident involved a hacker named “Andrew” who is reportedly attempting to extort Oracle Health customers and is demanding millions of dollars in cryptocurrency to prevent the publication of stolen data.
organisation
The Federal Bureau of Investigation
The Federal Bureau of Investigation is investigating, but does not divulge information about ongoing investigations.
data_breach
6 records
Oracle’s response relates to a claim by a threat actor – rose87168 – who is attempting to sell 6 million data records, including LDAP display names, email addresses, given names, hashed passwords, and other information.
April 15, 2025
Threat actors exploited a vulnerability in Oracle Health/Cerner's systems to breach sensitive data of nearly 20 million individuals.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
April 21, 2025
Threat actors have stolen sensitive data from Oracle's legacy cloud environment, which can be enriched with information from prior breaches and potentially sold to other threat actors or used for phishing campaigns.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
tactic
Data Breach
April 21, 2025: CISA issues Security Alert for Customers Affected by Oracle Data Breach
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a
security alert
about the recently confirmed Oracle data breach.
organisation
Oracle Data Breach
April 21, 2025: CISA issues Security Alert for Customers Affected by Oracle Data Breach
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a
security alert
about the recently confirmed Oracle data breach.
organisation
BEC
The stolen data can be enriched with information obtained in prior breaches, the information could be sold to other threat actors, and could be used to conduct BEC attacks or phishing campaigns.
organisation
Oracle
Oracle has confirmed that an unauthorized individual gained access to its legacy cloud environment, although limited details about the incident have been disclosed by Oracle, and the extent of the breach is currently unconfirmed.
August 14, 2025
Threat actors used unknown methods to target Oracle Health/Cerner, resulting in the breach of sensitive data affecting more than 14,480 confirmed individuals.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
December 30, 2025
Threat actors used unknown methods to target Oracle Health, resulting in the theft of patient data affecting up to 80 hospitals and potentially millions of individuals.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
tactic
Data Breach
…moment you acquire a company, you become responsible for all aspects of that company, and that includes its security vulnerabilities.”
December 30, 2025: 80 Hospitals May Have Been Affected by the Oracle Health Data Breach
The number of individuals affected by the hacking incident at Oracle Health has yet to be confirmed; however, the data breach is known to have affected up to 80 hospitals.
organisation
the Oracle Health Data Breach
…moment you acquire a company, you become responsible for all aspects of that company, and that includes its security vulnerabilities.”
December 30, 2025: 80 Hospitals May Have Been Affected by the Oracle Health Data Breach
The number of individuals affected by the hacking incident at Oracle Health has yet to be confirmed; however, the data breach is known to have affected up to 80 hospitals.
general_metric
80 Hospitals
…moment you acquire a company, you become responsible for all aspects of that company, and that includes its security vulnerabilities.”
December 30, 2025: 80 Hospitals May Have Been Affected by the Oracle Health Data Breach
The number of individuals affected by the hacking incident at Oracle Health has yet to be confirmed; however, the data breach is known to have affected up to 80 hospitals.
organisation
Lake Regional Health System
Lake Regional Health System in Missouri, OSF Saint Clare Medical Center in Illinois, Aultman Health System in Ohio, and NKC Health in North Kansas City have all recently confirmed that they were affected by the hacking incident and had patient data stolen.
organisation
OSF Saint Clare Medical Center
Lake Regional Health System in Missouri, OSF Saint Clare Medical Center in Illinois, Aultman Health System in Ohio, and NKC Health in North Kansas City have all recently confirmed that they were affected by the hacking incident and had patient data stolen.
organisation
NKC Health
Lake Regional Health System in Missouri, OSF Saint Clare Medical Center in Illinois, Aultman Health System in Ohio, and NKC Health in North Kansas City have all recently confirmed that they were affected by the hacking incident and had patient data stolen.
organisation
Munson Healthcare
One of the worst-affected healthcare clients was Munson Healthcare in Michigan, which has recently confirmed that more than 100,000 patients have been affected.
March 31, 2025:
Oracle Health and Cerner experienced a data breach affecting nearly 20 million individuals, with the exact date of discovery not specified in this snippet.
April 3, 2025:
A Florida resident filed a class action lawsuit against Oracle Corporation in the U.S. District Court for the Western District of Texas on April 3, 2025, alleging that the company was responsible for a January 2025 data breach affecting almost 20 million individuals.
Click on any entity below to view its context and source!
tactic
Data Breach
April 3, 2025: Oracle Sued Over Healthcare Data Breach
A class action lawsuit has been filed against Oracle Corporation by a Florida resident in the U.S. District Court for the Western District of Texas over a January 2025 data breach.
organisation
Healthcare Data Breach
April 3, 2025: Oracle Sued Over Healthcare Data Breach
A class action lawsuit has been filed against Oracle Corporation by a Florida resident in the U.S. District Court for the Western District of Texas over a January 2025 data breach.
organisation
Oracle Corporation
April 3, 2025: Oracle Sued Over Healthcare Data Breach
A class action lawsuit has been filed against Oracle Corporation by a Florida resident in the U.S. District Court for the Western District of Texas over a January 2025 data breach.
April 15, 2025:
Oracle confirmed a hacking incident on April 15, 2025.
Click on any entity below to view its context and source!
organisation
Oracle Confirms Hacking Incident
April 15, 2025: Oracle Confirms Hacking Incident
August 14, 2025:
At least 14,485 individuals are known to be affected by a data breach at Oracle Health/Cerner.
Click on any entity below to view its context and source!
tactic
Data Breach
…ssouri
Munson Healthcare
, Michigan
North Kansas City Hospital
, Missouri
OSF HealthCare, Illinois
Tallahassee Memorial Healthcare
, Florida
Union Health
, Indiana
August 14, 2025: At Least 14,485 Individuals Known to be Affected by Oracle Health/Cerner Data Breach
The number of individuals affected by a data breach at Oracle Health (formerly Cerner Corporation) is becoming clearer.
organisation
AdventHealth
…ssouri
Munson Healthcare
, Michigan
North Kansas City Hospital
, Missouri
OSF HealthCare, Illinois
Tallahassee Memorial Healthcare
, Florida
Union Health
, Indiana
August 14, 2025: At Least 14,485 Individuals Known to be Affected by Oracle Health/Cerner Data Breach
The number of individuals affected by a data breach at Oracle Health (formerly Cerner Corporation) is becoming clearer.
organisation
Baptist Health
…ssouri
Munson Healthcare
, Michigan
North Kansas City Hospital
, Missouri
OSF HealthCare, Illinois
Tallahassee Memorial Healthcare
, Florida
Union Health
, Indiana
August 14, 2025: At Least 14,485 Individuals Known to be Affected by Oracle Health/Cerner Data Breach
The number of individuals affected by a data breach at Oracle Health (formerly Cerner Corporation) is becoming clearer.
organisation
Mosaic Life Care
…ssouri
Munson Healthcare
, Michigan
North Kansas City Hospital
, Missouri
OSF HealthCare, Illinois
Tallahassee Memorial Healthcare
, Florida
Union Health
, Indiana
August 14, 2025: At Least 14,485 Individuals Known to be Affected by Oracle Health/Cerner Data Breach
The number of individuals affected by a data breach at Oracle Health (formerly Cerner Corporation) is becoming clearer.
organisation
Tallahassee Memorial Healthcare
…ssouri
Munson Healthcare
, Michigan
North Kansas City Hospital
, Missouri
OSF HealthCare, Illinois
Tallahassee Memorial Healthcare
, Florida
Union Health
, Indiana
August 14, 2025: At Least 14,485 Individuals Known to be Affected by Oracle Health/Cerner Data Breach
The number of individuals affected by a data breach at Oracle Health (formerly Cerner Corporation) is becoming clearer.
organisation
Florida
Union Health
…ssouri
Munson Healthcare
, Michigan
North Kansas City Hospital
, Missouri
OSF HealthCare, Illinois
Tallahassee Memorial Healthcare
, Florida
Union Health
, Indiana
August 14, 2025: At Least 14,485 Individuals Known to be Affected by Oracle Health/Cerner Data Breach
The number of individuals affected by a data breach at Oracle Health (formerly Cerner Corporation) is becoming clearer.
organisation
Oracle Health/Cerner Data Breach
…ssouri
Munson Healthcare
, Michigan
North Kansas City Hospital
, Missouri
OSF HealthCare, Illinois
Tallahassee Memorial Healthcare
, Florida
Union Health
, Indiana
August 14, 2025: At Least 14,485 Individuals Known to be Affected by Oracle Health/Cerner Data Breach
The number of individuals affected by a data breach at Oracle Health (formerly Cerner Corporation) is becoming clearer.
general_metric
14,485 Individuals
…ssouri
Munson Healthcare
, Michigan
North Kansas City Hospital
, Missouri
OSF HealthCare, Illinois
Tallahassee Memorial Healthcare
, Florida
Union Health
, Indiana
August 14, 2025: At Least 14,485 Individuals Known to be Affected by Oracle Health/Cerner Data Breach
The number of individuals affected by a data breach at Oracle Health (formerly Cerner Corporation) is becoming clearer.
October 2, 2026
Unauthorized individual gained access to legacy Cerner servers as early as January 22, 2025.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
organisation
OCR
The Texas Attorney General was provided with an updated total on October 2, 2026, so the OCR breach portal should be updated in the next few weeks.
organisation
The Oracle Health/Cerner
The Oracle Health/Cerner breach notice states that an unauthorized individual first gained access to legacy Cerner servers as early as January 22, 2025, and the security breach was identified by Oracle Health on March 7, 2025.
organisation
Oracle Health on March 7, 2025
The Oracle Health/Cerner breach notice states that an unauthorized individual first gained access to legacy Cerner servers as early as January 22, 2025, and the security breach was identified by Oracle Health on March 7, 2025.
Oct 8, 2026
Almost 20 million individuals' protected health information was compromised in a data breach involving Oracle Health's legacy Cerner servers.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Legal
General Document Context
tactic
Data Breach
Almost 20 Million Individuals Affected by 2025 Data Breach at Oracle Health/Cerner
Posted By
Steve Alder
on Oct 8, 2026
general_metric
20 Individuals
Almost 20 Million Individuals Affected by 2025 Data Breach at Oracle Health/Cerner
Posted By
Steve Alder
on Oct 8, 2026
data_breach
2025 Data Breach
Almost 20 Million Individuals Affected by 2025 Data Breach at Oracle Health/Cerner
Posted By
Steve Alder
on Oct 8, 2026
The scale of a 2025 data breach involving electronic protected health information stored on Oracle Health’s legacy Cerner servers is becoming clearer.
organisation
Oracle Health/Cerner
Posted
Almost 20 Million Individuals Affected by 2025 Data Breach at Oracle Health/Cerner
Posted By
Steve Alder
on Oct 8, 2026
organisation
Oracle Health’s
The scale of a 2025 data breach involving electronic protected health information stored on Oracle Health’s legacy Cerner servers is becoming clearer.
organisation
Oracle Health
Oracle Health has not publicly disclosed how many Cerner clients were affected, or the total number of individuals affected.
organisation
The HHS’ Office for Civil Rights
The HHS’ Office for Civil Rights breach portal lists the final total number of affected individuals, although it has yet to be updated with the latest figures and still lists the incident with a placeholder total of 501 individuals.
2026/10/08
Oracle Health/Cerner experienced a 2025 data breach affecting at least 14,485 residents across multiple states.
Click on any entity below to view its context and source!
organisation
Data Breach
Almost 20 Million Individuals Affected by 2025 Data Breach at Oracle Health/Cerner.
organisation
Oracle Health/Cerner
Almost 20 Million Individuals Affected by 2025 Data Breach at Oracle Health/Cerner.
data_breach
2025 Data Breach
Almost 20 Million Individuals Affected by 2025 Data Breach at Oracle Health/Cerner.
organisation
The HHS’ Office for Civil Rights
State
Affected State Residents
Massachusetts
6,562
Texas
4,082
South Carolina
2,989
Washington
802
California
Unknown
Total
At least 14,485 individuals
Oracle Health stated previously that it is the responsibility of each affected covered entity to determine if there has been a breach that requires reporting to the HHS’ Office for Civil R…
organisation
California
Unknown
Total
State
Affected State Residents
Massachusetts
6,562
Texas
4,082
South Carolina
2,989
Washington
802
California
Unknown
Total
At least 14,485 individuals
Oracle Health stated previously that it is the responsibility of each affected covered entity to determine if there has been a breach that requires reporting to the HHS’ Office for Civil R…
November, 11 months
Oracle Health/Cerner notified OSF Saint Clare Medical Center and NKC Health with a list of nearly 20 million affected individuals in November, approximately 11 months after the reported hacking incident.
2027/09/03
Threat actors compromised Oracle Health/Cerner's systems in 2025, resulting in the exposure of sensitive data that was not disclosed to affected individuals until November 2026.
Tactical Metrics
Metrics
data_breach
2,025
Data Breach
Click for context!
Almost 20 Million Individuals Affected by 2025 Data Breach at Oracle Health/Cerner.
Almost 20 Million Individuals Affected by 2025 Data Breach at Oracle Health/Cerner
Posted By
Steve Alder
on Oct 8, 2026
The scale of a 2025 data breach involving electronic protected health information stored on Oracle Health’s legacy Cerner servers is becoming clearer.
Metrics
financial
28,400,000,000
Deal
Oracle acquired Cerner Corporation in 2022 in a $28.4 billion deal, and merged the company into Oracle Health.
Metrics
financial
28,300,000,000
Acquisition
The lawsuit claims Oracle Health was negligent by failing to secure servers after the $28.3 billion acquisition of Cerner in 2022.
Metrics
data_breach
6,000,000
Records
In what appears to be a separate incident, another individual claims to have exploited a vulnerability around a month ago and accessed an Oracle Cloud server and exfiltrated approximately 6 million records.
Oracle’s response relates to a claim by a threat actor – rose87168 – who is attempting to sell 6 million data records, including LDAP display names, email addresses, given names, hashed passwords, and other information.
Metrics
victims
140,000
Customers
CloudSEK researchers reviewed the data provided by rose87168 and concluded with medium confidence that it rates high in severity and involved more than 140,000 customers who use Oracle Cloud services.
Intelligence Sources
HIPAA Journal
2026-10-08
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-09T06:09
Comprehensive Tactical Telemetry
Highly Correlated Entities
57x
organisation
Identified Entity
Data Breach
entity
30x
timeline
Temporal Reference
Oct 8, 2026
date
9x
general metric
Individuals
20,000,000
individuals
4x
tactic
Cyber Operation Type
Data Breach
tactic
2x
industry
Targeted Sector
Health
sector
2x
general metric
March
7
march
Contextual Telemetry
Context Block
14 METRICS
data breach
Data Breach
2,025
data breach
general metric
Hospitals
80
hospitals
vulnerability
Exploited CVE
CVE-2021-35587
cve
general metric
January
22
january
financial
Deal
28,400,000,000
deal
general metric
Patients
100,000
patients
general metric
Texas
6,562
texas
general metric
South Carolina
4,082
south carolina
general metric
Washington
2,989
washington
general metric
California
802
california
financial
Acquisition
28,300,000,000
acquisition
data breach
Records
6,000,000
records
victims
Customers
140,000
customers
general metric
February
20
february
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.