cypro.co.uk Oracle Health Breach Affects Nearly 20 Million Individuals
Article Content
- •Oracle's healthcare breach compromised data of nearly 20 million individuals.
- •Attackers accessed legacy Cerner infrastructure using compromised credentials.
- •The breach's scope includes at least 29 hospitals, with potential for more.
A cybersecurity breach at Oracle's healthcare unit compromised personal information of nearly 20 million people, as disclosed by the Texas Attorney General on October 2, 2026. The breach, which began in January 2025, involved attackers using compromised customer credentials to access legacy Cerner infrastructure. Among those affected, approximately 3 million individuals are from Texas. The scale of the breach is significant, with at least 29 hospitals and health systems acknowledging their involvement. Earlier estimates had reported around 14,485 individuals affected, but the new figure represents a substantial increase. The FBI has been investigating the cyberattack, which involved attempts to extort medical companies for ransom. The exact number of affected organizations may be higher than currently reported, with earlier estimates suggesting up to 80 hospitals could be involved. As of now, the total number of affected individuals has not been independently verified.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cerner in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How many individuals are affected?
What information was compromised?
What should affected organizations do?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…