“Representatives from these companies, all who agreed to confirm the data under the promise of anonymity, confirmed the authenticity of the information.”

Oracle said there was no breach of Oracle Cloud. Companies whose data appeared in the leak confirmed it was authentic. The login server was running Fusion Middleware 11g, open to a 2021 bug. The attacker even left a file with their own email address on Oracle’s server.