Oracle Health Data Breach Tally Climbs to Nearly 20 Million
Description
Nearly 20 million individuals had their personal and medical information compromised in a cyberattack on Oracle Health's legacy Cerner systems in early 2025. The breach involved unauthorized access via stolen customer credentials to a legacy server not yet migrated to Oracle Cloud. The compromised data includes names, Social Security numbers, medical records, diagnoses, medications, test results, and treatment information. The attacker demanded cryptocurrency ransom to prevent data leakage. This incident is among the largest healthcare data breaches in the US, with significant numbers of affected individuals reported across multiple states.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In early 2025, Oracle Health (formerly Cerner) experienced a cybersecurity incident involving unauthorized access to legacy servers containing patient data. The attacker used stolen customer credentials to access and copy data from the server. The breach was discovered around February 20, 2025, and affected nearly 20 million people, far exceeding earlier reported figures. The compromised data includes sensitive personal and medical information such as Social Security numbers and detailed patient medical records. The attacker attempted extortion by demanding millions in cryptocurrency and publicizing the breach to pressure victims. Notifications have been filed with multiple state regulators, including Texas, South Carolina, Washington, Oregon, and California. Oracle has not publicly commented on the total number of affected individuals.
Potential Impact
The breach exposed sensitive personal and medical information of nearly 20 million individuals, including Social Security numbers and detailed health records. This level of exposure poses significant risks of identity theft, fraud, and privacy violations for affected individuals. The incident is one of the largest healthcare data breaches in the US, impacting multiple states and healthcare providers. The attacker’s extortion attempts further increased the operational and reputational impact on Oracle Health and its customers.
Defensive Guidance
Oracle Health began notifying affected healthcare customers in March 2025 and has presumably taken steps to secure legacy systems and migrate data to Oracle Cloud. No public statement or official vendor advisory regarding remediation or patching is available. Patch status is not yet confirmed — check Oracle’s official communications and regulatory filings for current remediation guidance. Organizations using Oracle Health/Cerner systems should verify that legacy servers are fully migrated and secured, review access controls, and monitor for unauthorized credential use. No specific vendor-provided mitigation instructions are available in the provided data.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/oracle-health-data-breach-tally-climbs-to-nearly-20-million/","fetched":true,"fetchedAt":"2026-10-08T08:33:21.249Z","wordCount":1133}
Threat ID: 6ac755512cdf04f65600bc11
Added to database: 10/08/2026, 08:33:21 UTC
Last enriched: 10/08/2026, 08:33:26 UTC
Last updated: 10/08/2026, 14:33:24 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.