Summary

  • Software giant Oracle is yet to comment on recent reports of two data breaches, despite customer complaints.
  • The breaches have exposed sensitive information about thousands of Oracle’s customers, with one incident believed to have occurred in February.
  • In the first breach, threat actors are thought to have accessed a server owned by Oracle’s healthcare division, stealing patient data from US hospitals.
  • oracle’s healthcare division Seema Verma sent out breach notifications to customers, which were printed on plain paper rather than official company letterhead.
  • The second breach involved a hacker known as rose87168, who claimed to have acquired 6 million records of authentication data from the company’s cloud customers.
  • External security researchers have confirmed the legitimacy of the stolen data, estimated to have affected over 140,000 tenants.

By Dan Goodin

Original Article