Oracle Health Data Breach Tally Climbs to Nearly 20 Million
Oracle Health data breach impacts nearly 20 million individuals.
Summary
A cyberattack on Oracle Health's legacy Cerner systems has compromised the personal and medical information of nearly 20 million people, a figure significantly higher than initially reported. The breach, which occurred early last year, involved unauthorized access to data on an old server using stolen customer credentials. The threat actor, identified as 'Andrew,' demanded millions in cryptocurrency to prevent data leaks.
Full text
The personal and medical information of nearly 20 million people was compromised in a cyberattack on Oracle Health’s legacy Cerner systems early last year, Bloomberg reported, citing a report from the Texas attorney general. The figure is far higher than the counts that surfaced in earlier filings and patient notifications. Oracle has not made a public statement on the number of affected individuals and declined to comment to Bloomberg. Cerner, an electronic health record (EHR) vendor, became part of Oracle in June 2022, after a deal that valued the company at roughly $28.3 billion. The business now operates as Oracle Health. Oracle began alerting healthcare customers in March 2025. “We are writing to inform you that, on or around February 20, 2025, we became aware of a cybersecurity event involving unauthorized access to some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud,” its notice read. Oracle told customers that the available evidence suggested the attacker had used stolen customer credentials to access the server sometime after January 22, 2025, and had copied data to a remote server. Sources told BleepingComputer at the time that the extortion attempts against affected hospitals came from an individual threat actor known as ‘Andrew’. The actor had not claimed links to any established ransomware or extortion gang.Advertisement. Scroll to continue reading. To keep the stolen data from being leaked or sold, the hacker demanded millions of dollars in cryptocurrency, and set up public websites about the breach to increase pressure on the victims. Cerner’s entry on the Texas attorney general’s data breach portal, published on October 2, lists 2,992,244 affected Texans. Breach notifications filed in South Carolina and Washington list roughly 283,000 and 69,000 affected residents, respectively. Filings with Oregon regulators give January 22 through April 1, 2025, as the dates of the breach, and February 20, 2025, as the discovery date. A sample notification letter filed by Cerner with California regulators describes the types of data involved. “The personal information involved in this incident may have included your name, Social Security number, and information included within patient medical records, such as medical record numbers, doctors, diagnoses, medicines, test results, images, care and treatment,” the letter reads. If confirmed, the nearly 20 million figure would make the incident one of the largest healthcare data breaches on record in the US. Only a handful of reported incidents were bigger, including the 2024 ransomware attack on Change Healthcare, which affected 192.7 million people. Related: Healthcare Data Breaches Related: 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms Related: Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into ProxiesFBI Blames Contractor’s Missed Patch for ShinyHunters BreachCybersecurity M&A Roundup: 39 Deals Announced in September 2026Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated ReportsExploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days EarlierCrypto Scammers Hijack Microsoft’s Official X AccountAI Agents Aimed SQL Injection at US and Canadian Government SitesPolice Shut Down KillSec Ransomware, Identify Alleged Teen Leader Latest News Fake Decryption Tools Masked $11M Markup in Ransomware Recovery SchemeFortiBleed Attackers Locking Victims Out of Fortinet DevicesGeorgia Power, Alabama Power Data Breach Hits 400,000 AccountsQilin Ransomware Suspect Arrested in Japan, Extradited to GermanyHadrian Raises $40 Million to Expand Autonomous Offensive Security PlatformAdvantest Discloses Data Breach Months After Ransomware AttackChrome 155 Update Patches 247 VulnerabilitiesAnthropic Introduces 3-Tier Cyber Verification Program for AI Access Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.Lumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — Andrew