TechCrunch News 04月01日 02:24
Oracle under fire for its handling of separate security incidents
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

甲骨文公司近期因两起看似无关的数据泄露事件受到批评。其中一起事件似乎仍在发酵,尽管甲骨文否认发生了任何泄露。另一起事件涉及该公司医疗保健子公司Oracle Health的患者数据泄露。Oracle Health为医院和其他医疗保健提供商提供在线访问健康记录的技术。据报道,黑客访问了Oracle服务器并窃取了患者数据,并试图勒索受影响的医院。此外,黑客还在网络犯罪论坛上发布了600万Oracle Cloud客户的数据,包括身份验证数据和加密密码,尽管甲骨文否认发生了云端泄露。

🏥Oracle Health数据泄露事件:Oracle Health是甲骨文旗下的医疗保健子公司,为医疗机构提供技术支持,此次泄露事件涉及患者数据,具体数据类型和受影响机构尚不明确。

💰勒索事件:黑客访问Oracle服务器并窃取患者数据后,试图向受影响的医院勒索数百万美元。

☁️Oracle Cloud数据泄露事件:黑客在网络犯罪论坛上发布了600万Oracle Cloud客户的数据,包括身份验证数据和加密密码。尽管甲骨文否认发生泄露,但客户确认黑客分享的数据样本是真实的。

🗣️内部员工的担忧:甲骨文内部员工表示,公司在数据泄露事件上不够透明,员工甚至需要通过Reddit和Slack渠道了解情况。

📢专家观点:网络安全专家Kevin Beaumont和Lisa Forte都对甲骨文的处理方式表示担忧,认为公司需要公开透明地沟通事件,并承担责任。

Tech giant Oracle is facing criticism for how it’s handling two seemingly separate data breaches. 

At least one of the incidents appears to still be unfolding, despite Oracle reportedly denying a breach at all. The other relates to a breach of patient data under the tech giant’s healthcare subsidiary, Oracle Health.

Oracle did not respond to TechCrunch’s request for comment about the two incidents.

The breach disclosed most recently involves Oracle Health, which provides hospitals and other healthcare providers with technology to access health records online. Oracle Health is a unit that was combined with Cerner, an electronic health records company that Oracle acquired in 2022 for $28 billion.

Bloomberg and Bleeping Computer reported last week that the breach affects patient data, although it’s unclear exactly what kinds of data were stolen, nor which organizations and companies that use Oracle Health are affected. 

Oracle notified some of its healthcare customers in March of a breach that happened sometime earlier this year, in which hackers accessed Oracle servers and stole patient data, according to the publications.

Do you have more information about these two Oracle breaches? From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

“We are writing to inform you that, on or around February 20, 2025, we became aware of a cybersecurity event involving unauthorized access to some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud,” read the notification sent to some Oracle Health customers, according to Bleeping Computer. 

Citing multiple sources, the news site reported that a hacker is trying to extort affected hospitals, reportedly demanding millions of dollars. 

An Oracle employee, who asked to remain anonymous as they were not authorized to speak to the press, told TechCrunch that the company hasn’t been very transparent even with its own employees. 

“My team was not able to access customers’ environments for a number of days. My concern is not just with patient data breach. Access through hosts allows any and all access to what is hosted, obviously,” said the employee. “Some customers host other applications like HR and finance. I don’t know if it was hacker[-]accessed though.”

The employee said they had to look at Reddit and internal Slack channels “to even figure out something was being looked at.”

The employee said they “felt super ignored,” describing the situation as: “Nothing to see here, move right along.”

The employee, however, also said that they saw on Slack that some teams were given language to communicate with clients on March 4: “We will investigate the issue you are experiencing.”

The other separate breach involves Oracle Cloud servers. And in this case too, Oracle is not being very transparent about what happened. 

Earlier this month, a hacker going by the online handle rose87168 posted on a cybercrime forum offering the data of six million Oracle Cloud customers, including authentication data and encrypted passwords, as Bleeping Computer reported at the time. 

To prove that they breached Oracle, rose87168 uploaded a text file containing their online handle that was hosted on an Oracle Cloud server.

A screenshot of the archived text file that rose87168 uploaded to an Oracle server. (Image: TechCrunch)

Since, several Oracle customers have confirmed that data samples shared by the hacker appear genuine, pointing to further evidence of a breach at Oracle.

Strangely, Oracle denied that there was a breach at all. 

“There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data,” Oracle told the publication.

But not everyone is convinced. 

“This is a serious cybersecurity incident which impacts customers, in a platform managed by Oracle,” cybersecurity expert Kevin Beaumont wrote in a blog post analyzing the alleged Oracle Cloud breach. “Oracle are attempting to wordsmith statements around Oracle Cloud and use very specific words to avoid responsibility. This is not okay.” 

“Oracle need to clearly, openly and publicly communicate what happened, how it impacts customers, and what they’re doing about it. This is a matter of trust and responsibility. Step up, Oracle — or customers should start stepping off,” said Beaumont.

Commenting on one of the alleged Oracle breaches, cybersecurity expert Lisa Forte wrote on Bluesky that, “if this ends up being true, and I struggle to see how it won’t, this is a very very bad look.”

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

甲骨文 数据泄露 网络安全 Oracle Health Oracle Cloud
相关文章