Oracle grapples with dual data breaches


Oracle is dealing with the fallout of a double data breach — one exposing patient data at US hospitals, and another raising concerns about its cloud security.

Reports over the weekend suggest a breach at Oracle Health, formerly known as Cerner, has impacted multiple US healthcare organisations and hospitals. Threat actors are believed to have stolen patient data from legacy servers during the attack. In a notice seen by BleepingComputer, Oracle Health said the attackers had accessed Cerner data stored on an old server that had not yet been migrated to Oracle Cloud. Oracle Health informed affected customers that it became aware of the breach on 20th February, after detecting unauthorised access to its legacy Cerner data migration servers.

Read more…
Source: Computing News


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Sperm bank breach deposits data into hands of cybercriminals

    March 19, 2025

    Sperm donor giant California Cryobank has announced it has suffered a data breach that exposed customers’ personal information. California Cryobank (CCB) is a sperm donation and cryopreservation firm and one of the US’ top sperm banks. As such, it services all US states and over 30 countries worldwide. The data breach notification states that the breach ...

  • Critical Security Incident involving GitHub Action tj-action/changed-files

    March 17, 2025

    A critical security incident involving the tj-actions/changed-files GitHub Action has been reported. The changed-files action, which allows GitHub repositories to track file changes, has been tampered with to allow the exposure through GitHub Actions build logs of CI/CD secrets, including passwords, tokens, API keys, PII and other sensitive data that have been embedded within software code. ...

  • Amazon is still hosting spyware victims’ data weeks after breach alert

    March 13, 2025

    Amazon will not say if it plans to take action against three phone surveillance apps that are storing troves of individuals’ private phone data on Amazon’s cloud servers, despite TechCrunch notifying the tech giant weeks earlier that it was hosting the stolen phone data. Amazon told TechCrunch it was “following process” after our February notice, ...

  • Bank Of America Alerts Customers To Data Breach, Offers Identity Theft Protection For Affected Accounts

    March 11, 2025

    The Bank of America has alerted a small group of its customers about a data breach that may have exposed confidential information. The breach, which took place on December 30, was a result of improper handling of confidential documents by a third-party document destruction service provider. The breach could have potentially exposed sensitive data, including personal ...

  • Hacker accessed PowerSchool’s network months before massive December breach

    March 10, 2025

    A hacker compromised the U.S. edtech giant PowerSchool months before its ‘massive’ data breach in December, according to a now-published forensic report into the incident conducted by U.S. cybersecurity firm CrowdStrike. In a letter sent to affected customers last week, seen by TechCrunch, PowerSchool confirmed that an investigation into the incident has revealed that its network ...

  • Allstate sued for not reporting data breach of 165,000 New Yorkers

    March 10, 2025

    New York state sued Allstate on Monday, accusing the insurer’s National General unit of failing to report a data breach that exposed drivers’ license numbers, and not developing reasonable safeguards to protect policyholders’ private information. The lawsuit by New York Attorney General Letitia James was filed in a state court in Manhattan, and seeks civil fines. ...