Oracle Health breach tally climbs to nearly 20 million people

· CyberSecurity

TLDR

  • A Texas attorney general report, first reported by Bloomberg, puts the toll of Oracle Health's 2025 Cerner breach at nearly 20 million people, far above the counts in earlier filings and patient notification letters.12
  • Attackers used stolen customer credentials to access an old legacy Cerner server not yet migrated to Oracle Cloud, copying data sometime after 22 January 2025; Oracle began notifying healthcare customers in March 2025.1
  • A lone threat actor known as "Andrew," not linked to any established ransomware or extortion gang, demanded millions of dollars in cryptocurrency and set up public pressure websites threatening to leak the stolen data.1
  • If confirmed, the nearly-20-million figure would make this one of the largest healthcare data breaches on record in the US, behind only a handful of incidents including the 192.7 million-person Change Healthcare attack.2

Cerner, the electronic health record vendor Oracle acquired in June 2022 for roughly $28.3 billion and now operates as Oracle Health, told affected customers in March 2025: "We are writing to inform you that, on or around February 20, 2025, we became aware of a cybersecurity event involving unauthorized access to some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud."1 Oracle said available evidence suggested the attacker used stolen customer credentials to access the server after 22 January 2025 and copied data to a remote server.1 Oracle has not made a public statement on the number of affected individuals and declined to comment to Bloomberg.12

The scale only became clear through state regulatory filings rather than any Oracle disclosure. Cerner's entry on the Texas attorney general's data breach portal, published 2 October, lists 2,992,244 affected Texans, with notifications sent by US mail; separate filings in South Carolina and Washington list roughly 283,000 and 69,000 affected residents.12 A sample notification letter filed with California regulators describes the exposed data as potentially including "your name, Social Security number, and information included within patient medical records, such as medical record numbers, doctors, diagnoses, medicines, test results, images, care and treatment."1 Oregon filings date the breach to between 22 January and 1 April 2025, with discovery on 20 February 2025.1

Sources previously told BleepingComputer that extortion attempts against affected hospitals came from an individual threat actor known as "Andrew," who had not claimed ties to any established ransomware or extortion gang and demanded millions of dollars in cryptocurrency while setting up public websites about the breach to pressure victims.1 Becker's reports at least 29 hospitals and health systems have been affected, that Oracle Health faces litigation over the incident, and that the FBI investigated both the intrusion and the extortion attempts; Oracle's healthcare customers include the Defense Department and the Department of Veterans Affairs, though a VA spokesperson said the agency was not affected.2

Why it matters: nearly 20 million people learning of their exposure only through a state attorney general's filing, more than a year and a half after the breach and with Oracle still not confirming a number, underscores how little visibility patients get into the scale of healthcare breaches until lawyers and regulators force it into the open.

Sources

  1. Oracle Health Data Breach Tally Climbs to Nearly 20 Million (SecurityWeek)
  2. Oracle Health breach exposed data of nearly 20 million people (Becker's Hospital Review)