The Register Home Page

back to article There are 10,000 reasons to doubt Oracle Cloud's security breach denial

Oracle Cloud's denial of a digital break-in is now in clear dispute. A infosec researcher working on validating claims that the cloud provider's login servers were compromised earlier this year says some customers have confirmed data allegedly stolen and leaked from the database giant is genuine. Since Oracle rubbished reports …

  1. NoneSuch Silver badge
    Devil

    Reality : 1

    Oracle: 0

    1. David 132 Silver badge

      I'm not one for victim-blaming, and the blame & odium belong squarely on the miscreant, but I will say... this couldn't happen to a nicer and more deserving company than Oracle. Nyuk, nyuk.

      1. ChrisBedford

        The problem is the actual victims here aren't Oracle

        I used to be a customer of a DNS server service that Oracle bought out. Cancelled that account at least 8 years ago. I still receive updates from them warning about planned maintenance outages. I clicked the "unsubscribe" link, they kep on coming. I complained to "support", who gave me every assurance that my email had been removed from the databse. They kept on coming. I replied to the support email calling them liars, and they just stopped responding. It wouldn't surprise me at all if I was to find out they have blocked my email address for receiving.

        And yet the emails keep on coming. Really tight internal IT department, this company. What's their business again? Oh, IT services? OK then.

        1. Andrew Barr

          Re: The problem is the actual victims here aren't Oracle

          Put a request in to the ICO as a GDPR breach, as they shouldnt be storing PII for longer than necessary.

        2. teknopaul

          Re: The problem is the actual victims here aren't Oracle

          It took me a while to get off that DNS service too.

          I block all @oracle.com emails.

          Thoughts and prayers to the poor sods forced into Oracle's cloud.

        3. Anonymous Coward
          Anonymous Coward

          Re: The problem is the actual victims here aren't Oracle

          Assuming you're in the UK or EU, you can use your Right to Erasure (yes, even in a business capacity if it relates to a person not a generic business address).

          They are require by law to remove you. If they don't, you can complain, and they will be fined (and you'll also have the satisfaction that you caused them untold hours and cost of processing the complaint).

          Even if you're not in the EU, big companies are generally so spooked by this that they'll blindly process any requests they get that fit the template.

          You don't even need to do anything in this day and age, just get ChatGPT to bang out the request and email it to them.

        4. Anonymous Coward
          Anonymous Coward

          Re: The problem is the actual victims here aren't Oracle

          What has mailing list management got to do with IT?

          I have clients that run mailing lists, I just look after the tech...I don't manage who is on the lists...because if I did, there would be no list.

    2. Peter-Waterman1

      I remember Larry going on stage at Oracle world some years back, it’s on you tube, and the dude literally spends 10 minutes attacking AWS security. Talking about how Oracle cloud 2.0 was vastly superior yada yada yada.

      Why he was using his keynote to give airtime about AWS I don't know, but its kind of ironic rhat a few years later it turns out their security is crap.

      1. MachDiamond Silver badge

        "Why he was using his keynote to give airtime about AWS I don't know, but its kind of ironic rhat a few years later it turns out their security is crap."

        Security is expensive and a constantly moving shield to keep in place. That severely impacts executive bonuses and earnings reports. Oracle AND AWS's customers are often operations a few orders of magnitude smaller. Complaints are the mews of a kitten in a box so the "good enough" bar winds up being set rather low.

        My hypothesis is that the size ratio can lead to a real ambivalence about security, customer satisfaction or quality. My cable internet company has millions of subscribers nationwide. A complaint from me winds up in a dead letter box after the "don't reply to this email, this account is not monitored" form letter is sent. I was supposed to receive some new gubbins to take advantage of higher speeds. I called to make sure it would ship to the correct address (not the service address) and was assured it was all set. It was sent to the service address, claims to have been delivered and isn't anything I've seen remaining on the doorstep a few meters from the road in plain view (which is why nothing gets shipped to the house). I get letters reminding me to install said gear from email addresses that can't be replied to and signed by a VP of customer satisfaction that doesn't have a locateable email address on the company web site. No inquiries asking if I received the gear. The upside is that I never signed for anything so there's no proof I have it. Fat lot of good that will do when their lawyers come calling at some point demanding I pay for it.

      2. Anonymous Coward
        Anonymous Coward

        Lets be fair here...Amazon has had it's fair share of security mishaps...they're all crap.

        1. NoneSuch Silver badge
          Pint

          Everyone has a security issue at some point.

          Or as I call it, job security.

    3. EdSaxby

      I'd describe it as "a glitch".

      Nothing to see here.

  2. Fruit and Nutcase Silver badge
    Coat

    Employment

    The price for the entire trove of data isn't known, but rose87168 said they'd happily accept cash or zero-day exploits for their trouble.

    Oracle could offer a consultancy to rose87168. May be sweeten the deal with an invitation to lunch with Larry in one of his yachts?

    1. Paul Herber Silver badge

      Re: Employment

      Oracle goon squad - he's fallen in the water!

    2. EnviableOne Silver badge

      Re: Employment

      Tried, Rose87168 asked for 100k Monero (approx. £20m) to disclose the details, fix it, and destroy the data, which Larry's Lawsuit House declined.

      From the posting, Rose sounds like someone who is very green and lucked into an exploit on a big fish.

      also possibly someone not entirely of an age to benefit from a work contract with Big Red.

      1. Anonymous Coward
        Anonymous Coward

        Re: Employment

        Asking for that much money, he has clearly never written a quote before that's for sure.

  3. Tron Silver badge

    Fun stuff for Bob and Jenny to do at the office.

    Reduce your cloud footprint.

    Unless you really, really need your data to be on a[ny] cloud, archive it on those very cheap multi-Tb HDDs you can now buy for peanuts, with as many copies as you need, and store it somewhere safe. offline.

    And don't store data for the sake of it. Only if you have a valid reason to store it. If you are never going to need it, you may as well be paying to archive and curate dust, collected each day by your cleaners.

    1. Steve K

      Re: Fun stuff for Bob and Jenny to do at the office.

      The Cloud is not just data storage..

    2. iRadiate

      Re: Fun stuff for Bob and Jenny to do at the office.

      Cloud = Data Storage?

      You need to educate yourself

      1. Richard 12 Silver badge

        Re: Fun stuff for Bob and Jenny to do at the office.

        True. It's just someone else's computer.

        They can turn it off or accidentally hand over control over everything to some random Rose on the Internet, and there's basically nothing you can do about it.

    3. rafff

      Re: Fun stuff for Bob and Jenny to do at the office.

      "If you are never going to need it, you may as well be paying to archive and curate dust"

      Every company has lots of data they are never going to use, but are required by law to keep - sometimes indefinitely.

      (Of course, they can wind up the company; that eliminates the data retention obligation.)

      1. Anonymous Coward
        Anonymous Coward

        Re: Fun stuff for Bob and Jenny to do at the office.

        Then keep it offline - not more publicly attackable than if they hosted it on their own systems!

      2. MachDiamond Silver badge

        Re: Fun stuff for Bob and Jenny to do at the office.

        "but are required by law to keep - sometimes indefinitely."

        What would need to be archived indefinitely? Usually there are statutes of limitations for tax and employee records that don't go beyond 10 years. It's also a good idea to maintain historical data on products and could be contractual requirements to do so. As the records from my closed manufacturing company age, there's boxes of paperwork each year that can be run through the shredder and used for animal bedding. The bird boxes on my property get a refresh of shredded paper every season and the birds seem to like it as they don't kick it out during nest building.

        1. Richard 12 Silver badge
          Pirate

          Re: Fun stuff for Bob and Jenny to do at the office.

          There are a few things that have to be kept for what could be the entire lifetime of the corporate body - and even through the zombie period in case of resurrection.

          But not many, and they're not large. Mostly contracts, tax and employment data.

          Eg your contract of employment needs to be retained, provably unaltered, until several years after you leave, in case you decide to sue.

          Most things can vanish though, and the vast majority of data so treasured has a negative real value, and should be destroyed almost immediately, or (better) never collected at all.

        2. Zwack

          Re: Fun stuff for Bob and Jenny to do at the office.

          What might need to be kept indefinitely? Some states have medical records requirements that amount to keeping them practically indefinitely.

          There can be different requirements in different states.

    4. MachDiamond Silver badge

      Re: Fun stuff for Bob and Jenny to do at the office.

      "Unless you really, really need your data to be on a[ny] cloud, archive it on those very cheap multi-Tb HDDs you can now buy for peanuts, with as many copies as you need, and store it somewhere safe. offline."

      An aerospace company I worked for had a server onsite that backed up each night to two other company locations in widely separated locations across the US in addition to local backups performed at all three. We had to keep it in-house for ITAR reasons, but there was no point in paying some third party to store our data.

    5. CtrlAltDeleteCloud

      Re: Fun stuff for Bob and Jenny to do at the office.

      Tape, USB sticks, dusty HDDs — all fair game if you’ve got the discipline.

      But for the rest of us who’ve seen one too many "Oops, we got encrypted" stories, going offline needs to be more than just cheap drives and wishful thinking.

      There’s stuff out there now that gives you true air-gapped immutability without the babysitting — no firmware updates, no admin backdoors, no phoning home.

      Think of it as tape’s revenge arc — minus the rewind button.

  4. Secure Strategy

    It's the SaaS apps that are the danger

    Most of those affected won't be directly using Oracle Cloud. They'll be using NetSuite, or another SaaS app (Zoom etc) that runs on Oracle Cloud. A quick look at the domains affected will show this - lots of SMEs .This needs to be called out in the article.

  5. Pascal Monett Silver badge

    So, when's the lawsuit ?

    And will it be class action ?

    Given the amount of data pilfered, I'm guessing a lot of CEOs are likely to be quite unhappy about this mess and will be wanting more than just excuses.

    1. Richard 12 Silver badge

      Re: So, when's the lawsuit ?

      Individual lawsuits. Corporations tend not to do class action, they have their own lawyers.

      1. MachDiamond Silver badge

        Re: So, when's the lawsuit ?

        "Corporations tend not to do class action, they have their own lawyers."

        They will also want more than $2.67 in compensation/damages.

  6. Jflynn007

    In related news

    Oracle has announced their new super duper advanced cloud security solution. Subscription based and charges by the byte of data. Free credits for any data lost.

  7. Dan 55 Silver badge
    FAIL

    CVE-2021-35587 9.8 critical

    This is why Oracle Cloud is reassuringly expensive.

  8. sanmigueelbeer

    Lawyers, start your engines!

  9. toby mills

    UAE seems to disagree with oracle

    https://www.thenationalnews.com/news/uae/2025/03/25/uae-government-confirms-public-and-private-sector-targeted-in-massive-global-hack/

    1. EnviableOne Silver badge

      the UAE have enough money, they should be able to survive an Oracle defamation sue-ball

  10. JpChen

    The irony here is that Oracle didn’t see this coming,

  11. Mitoo Bobsworth

    The new American paradigm...

    "It wasn't us - It's the other guys fault!"

  12. MichaelGordon

    I assume the laws are different in the US. If this had happened in the UK then Oracle would have been legally required to report the breach to the ICO within 72 hours of becoming aware of it. Failure to do so would have exposed them to a fine of up to £8.7 million or 2% of global turnover.

  13. TheBruce

    Headlines 24 Years Ago

    Ellison: Oracle remains unbreakable

    1. Anonymous Coward
      Anonymous Coward

      Re: Headlines 24 Years Ago

      It wasn't true then, either.

  14. xyz123 Silver badge

    oracle's state-of-the-art system/software has slightly less security than keeping your data on the desktop in a plaintext file called not_a_secret.txt

    Seriously. Remotely...2-3mins to access ANY oracle subsystem. With local access, you're down to less than 30seconds to have full admin control of an entire database.

  15. xyza

    I can point who is rose87168 ;)

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like