Gizmodo Oracle Health Data Breach Exposes 20 Million Patient Records
Article Content
- •Oracle Health's breach affects 20 million individuals, exposing sensitive health data.
- •The attack exploited legacy Cerner servers using compromised customer credentials.
- •Oracle initially denied the breach but later confirmed it in private communications.
A significant data breach at Oracle Health has reportedly compromised the personal data of approximately 20 million individuals. The breach, which involved unauthorized access to legacy Cerner servers, was initially suspected in March 2025 when a hacker named rose87168 claimed to have stolen 6 million health records. Oracle Health privately informed affected customers that the breach occurred around February 20, 2025, using compromised customer credentials. The stolen data includes sensitive medical details, addresses, and Social Security numbers. Investigations are ongoing, with cybersecurity firm CrowdStrike and the FBI involved. Oracle has faced criticism for initially denying the breach, claiming no Oracle Cloud customers were affected. The breach's impact extends to multiple U.S. healthcare organizations and hospitals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Cerner in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What data was compromised?
How did the breach occur?
What is Oracle doing about the breach?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…