
THREAT LEVEL - HIGH
28-03-2025
Oracle Cloud Breach Exposes Multitenant Identity Data
Threat Level Description
IthacaLabs has maintained the Threat Level (High) adding a new observation:
An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.
Description
We have observed an Oracle breach, which presents strong indicators of a data breach involving Oracle Cloud infrastructure, has been identified.
The incident centers around the public release of what appears to be internal Oracle Cloud Identity data, including user account credentials, tenant information, authentication hash values, and privileged group associations. The leaked data suggests a breach involving a production Single Sign-On (SSO) endpoint, reportedly impacting over 140,000 Oracle Cloud tenants.
The data leak appears to impact multiple organizations — evidenced by a variety of domains within the compromised user credentials — indicating a broader exposure than initially assumed. The leaked information includes sensitive identifiers such as tenant GUIDs, internal usernames, email addresses, account status, and password-related metadata, which could be used for further exploitation.
Organizations using Oracle Cloud Identity and Access Management (IAM), or integrating with Oracle services, may be at risk of credential-based attacks, privilege escalation, supply chain threats, and reputational damage.
Immediate actions are recommended to assess potential exposure and mitigate any ongoing risk. Organizations should treat this event as a high-priority incident and review any integrations with Oracle Cloud services to ensure the security of their environments.
Our Advisory and Managed Services, including our Security Operations and Technology Resilience lines, can help safeguard your organization against such threats.
Through proactive monitoring, threat detection, and incident response, our services are designed to keep your systems secure, resilient, and prepared for evolving cyber risks. We advise all organizations to remain vigilant and regularly review their cybersecurity postures.
Recommendation(s):
- Conduct an audit of all Oracle Cloud users and IAM roles for suspicious access patterns or privilege anomalies.
- Enforce mandatory password resets for users potentially affected by the breach.
- Enable and enforce Multi-Factor Authentication (MFA) across all Oracle Cloud accounts.
- Review and restrict any external integrations or directory syncs involving Oracle IAM.
- Monitor for credentials associated with your domains in breach databases and forums.
- Engage with Oracle representatives to validate the status of your tenant and request a formal security review.
- Increase awareness among employees about phishing threats and potential credential reuse.
- Ensure your incident response team is ready to respond to any suspicious activity related to Oracle integrations.



