2025 Oracle Health breach compromised data of nearly 20 million people 

A 2025 cyberattack targeting Oracle’s healthcare business compromised personal and medical information belonging to nearly 20 million people, including approximately 3 million Texans, according to newly released information from the Texas attorney general, Bloomberg reports.

The stolen information included Social Security numbers, addresses and medical information. Healthcare providers affected by the incident have said compromised records could also include patient names, diagnoses, medications, doctors and test results. Oracle initially notified customers of the breach in March 2025 but did not disclose how many patients were affected.

Attackers gained access to older servers belonging to Cerner, the electronic health records company Oracle acquired for $28 billion in 2022. Oracle told customers that the affected data had not yet been migrated from those legacy systems to Oracle’s cloud infrastructure.

The attack occurred sometime after January 22, 2025 and affected numerous Oracle healthcare customers, including hospitals and health systems. The FBI investigated the breach and attempts by the hackers to extort affected healthcare organizations. The newly disclosed figure provides the first indication of the nationwide scale of the incident.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“A cloud migration can increase breach risk when the migration server still holds the records attackers want. Oracle Health told affected customers in March 2025 that attackers had used compromised customer credentials to access older Cerner servers after January 22 and copy patient data to a remote location.

“Those servers sat outside Oracle Cloud because the data had not yet been migrated. Oracle acquired Cerner for $28 billion in 2022, but moving the destination did not remove the older copy. That is a data-lifecycle failure.

“I would treat every migration server holding patient data as a live clinical system until its access is separately controlled, its activity is logged, and its final copy is deleted. “Legacy” describes ownership and age. It does not describe the value of the data.

“The scale makes the lesson harder to ignore. Information belonging to nearly 20 million people was compromised, including about 3 million Texans. Hospitals also faced extortion attempts connected to the stolen records.

“Healthcare providers will keep moving records between vendors, platforms, and acquisition-era systems. If temporary migration environments receive weaker controls than production systems, attackers will target the copy that organizations have already stopped watching.”

Damon Small, Board of Directors, Xcape, Inc.:

“Exfiltrating nearly 20 million patient records proves that technical debt in healthcare M&A presents immediate, catastrophic operational liability. When Oracle acquired Cerner for $28 billion, inherited legacy systems remained unmigrated, leaving Social Security numbers and medical histories exposed to credential compromise and cyber extortion. The market reality directly refutes Larry Ellison’s bold assertion that “Oracle is unhackable.” Healthcare IT data is just as critical as the patients themselves, meaning software vendors and healthcare providers must treat electronic health records (EHR) as life-safety biomedical devices rather than basic back-office IT assets. Compromised EHR data unleashes severe risks, including long-term identity theft, medical insurance fraud, and targeted extortion. Security leadership must mandate multi-factor authentication, rigid network isolation, and deep logging across all unmigrated environments while treating legacy infrastructure as high-risk untrusted enclaves.”

“Critical Takeaways:

  • Classify EHR systems as mission-critical biomedical devices rather than standard back-office IT infrastructure.
  • Treat legacy systems inherited during M&A as untrusted enclaves with enforced multi-factor authentication, zero-trust network isolation, and centralized logging.
  • Prepare incident response strategies for high-impact post-exfiltration risks, including patient extortion, insurance fraud, and identity theft.

“It turns out “unhackable” legacy servers are surprisingly easy to hack.”

John Strand, Owner, Black Hills Information Security, Inc.:

“This news story should serve as a warning for anybody looking to acquire another company. Security due diligence absolutely needs to be part of the mergers and acquisitions process. It’s something we spend a lot of time doing for our customers. I don’t like the fact that Oracle is kind of hand-waving this away by saying these were legacy systems that hadn’t been migrated to their secure cloud services yet. They’re still responsible. The moment you acquire a company, you become responsible for all aspects of that company, and that includes its security vulnerabilities.”

I would love to say that Oracle learned its lesson from this. But the cynic in me says not so much. And that’s a shame.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading