Skip to main content

Oracle Health Data Breach Tally Climbs to Nearly 20 Million

0
High
Breach
Published: 10/08/2026 (10/08/2026, 08:23:31 UTC)
Source: SecurityWeek

Description

Nearly 20 million individuals had their personal and medical information compromised in a cyberattack on Oracle Health's legacy Cerner systems in early 2025. The breach involved unauthorized access via stolen customer credentials to a legacy server not yet migrated to Oracle Cloud. The compromised data includes names, Social Security numbers, medical records, diagnoses, medications, test results, and treatment information. The attacker demanded cryptocurrency ransom to prevent data leakage. This incident is among the largest healthcare data breaches in the US, with significant numbers of affected individuals reported across multiple states.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 08:33:26 UTC

Technical Analysis

In early 2025, Oracle Health (formerly Cerner) experienced a cybersecurity incident involving unauthorized access to legacy servers containing patient data. The attacker used stolen customer credentials to access and copy data from the server. The breach was discovered around February 20, 2025, and affected nearly 20 million people, far exceeding earlier reported figures. The compromised data includes sensitive personal and medical information such as Social Security numbers and detailed patient medical records. The attacker attempted extortion by demanding millions in cryptocurrency and publicizing the breach to pressure victims. Notifications have been filed with multiple state regulators, including Texas, South Carolina, Washington, Oregon, and California. Oracle has not publicly commented on the total number of affected individuals.

Potential Impact

The breach exposed sensitive personal and medical information of nearly 20 million individuals, including Social Security numbers and detailed health records. This level of exposure poses significant risks of identity theft, fraud, and privacy violations for affected individuals. The incident is one of the largest healthcare data breaches in the US, impacting multiple states and healthcare providers. The attacker’s extortion attempts further increased the operational and reputational impact on Oracle Health and its customers.

Defensive Guidance

Oracle Health began notifying affected healthcare customers in March 2025 and has presumably taken steps to secure legacy systems and migrate data to Oracle Cloud. No public statement or official vendor advisory regarding remediation or patching is available. Patch status is not yet confirmed — check Oracle’s official communications and regulatory filings for current remediation guidance. Organizations using Oracle Health/Cerner systems should verify that legacy servers are fully migrated and secured, review access controls, and monitor for unauthorized credential use. No specific vendor-provided mitigation instructions are available in the provided data.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/oracle-health-data-breach-tally-climbs-to-nearly-20-million/","fetched":true,"fetchedAt":"2026-10-08T08:33:21.249Z","wordCount":1133}

Threat ID: 6ac755512cdf04f65600bc11

Added to database: 10/08/2026, 08:33:21 UTC

Last enriched: 10/08/2026, 08:33:26 UTC

Last updated: 10/08/2026, 14:33:24 UTC

Views: 26

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses