Skip to content
Oracle Health Data Breach Exposes 20 Million Patient Records

Oracle Health Data Breach Exposes 20 Million Patient Records

First seen 6 Oct 2026, 17:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 18:04 UTC
  • •Oracle Health's breach affects 20 million individuals, exposing sensitive health data.
  • •The attack exploited legacy Cerner servers using compromised customer credentials.
  • •Oracle initially denied the breach but later confirmed it in private communications.

A significant data breach at Oracle Health has reportedly compromised the personal data of approximately 20 million individuals. The breach, which involved unauthorized access to legacy Cerner servers, was initially suspected in March 2025 when a hacker named rose87168 claimed to have stolen 6 million health records. Oracle Health privately informed affected customers that the breach occurred around February 20, 2025, using compromised customer credentials. The stolen data includes sensitive medical details, addresses, and Social Security numbers. Investigations are ongoing, with cybersecurity firm CrowdStrike and the FBI involved. Oracle has faced criticism for initially denying the breach, claiming no Oracle Cloud customers were affected. The breach's impact extends to multiple U.S. healthcare organizations and hospitals.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-01-22
Breach detected
Unauthorized access to legacy Cerner data migration servers began after this date.
BleepingComputer
2025-02-20
Oracle confirms breach to customers
Oracle Health informed affected customers about unauthorized access to legacy data.
BleepingComputer
2026-10-06
Public disclosure of breach impact
Texas Attorney General reports that 20 million people's data was involved in the breach.
Gizmodo

More articles in this cluster (5)

Following this threat?

Track Cerner in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What data was compromised?
The breach exposed sensitive personal data, including medical details, addresses, and Social Security numbers of approximately 20 million individuals.
How did the breach occur?
The attackers exploited compromised customer credentials to gain unauthorized access to legacy Cerner servers.
What is Oracle doing about the breach?
Oracle has engaged cybersecurity firm CrowdStrike and the FBI to investigate the incident and has communicated with affected customers.