Wednesday, October 7, 2026

Technology

Oracle Health Suffers Massive Cyberattack Exposing 20 Million People's Data

A massive cyberattack against Oracle Health has exposed the sensitive personal data of almost 20 million people.

Oracle Health Hack Exposes Data of Nearly 20M People
Source: CNET

A massive cyberattack against Oracle Health has exposed the sensitive personal data of almost 20 million people, according to a report from the Texas attorney general's office.

The compromised information includes Social Security numbers, addresses, and medical records, which were accessed by the attacker after January 22, 2025. Oracle officials disclosed this information to investigators and informed some customers about the breach in March of that year.

Oracle Health is a division of the tech giant Oracle, which acquired healthcare technology company Cerner for $28.3 billion in June 2022 as part of its expansion into the healthcare sector.

The attack targeted older servers belonging to Cerner before they were migrated to Oracle's cloud storage service, allowing hackers to exploit customer credentials and access patient data from two compromised servers, according to a cybersecurity firm based in the UK.

The hacking incident has significant implications for healthcare providers across the country, particularly in Texas where nearly 3 million residents were affected.

Several prominent hospitals and clinics in Texas are among those impacted by the breach, including Christus Health, a nonprofit healthcare system that serves patients in various parts of the state. In California, Tri-City Medical Center also reported being affected by the attack.

Christus Health has stated that compromised patient data may include sensitive information such as names, Social Security numbers, medical diagnoses, prescribed medications, and test results. The company is taking proactive steps to notify affected patients and provide them with additional protection.

CyPro, a cybersecurity consulting firm, has noted that at least 29 hospital and health systems have reported being impacted by the breach, highlighting the widespread nature of the incident.

The Oracle health data breach has left millions of people vulnerable to scams and identity theft, experts warn.

Stolen data can be used to make scam attempts more convincing if the perpetrators have access to personal details such as names, addresses, or healthcare information. Cliff Steinhauer, director of information security and engagement at the National Cybersecurity Alliance, advises individuals to be cautious when receiving unsolicited calls claiming to be from insurance providers or medical organizations.

People whose data was compromised in the breach should take steps to protect themselves by monitoring their credit reports, financial accounts, and healthcare statements for any suspicious activity. Steinhauer also recommends freezing credit with all three major credit reporting bureaus as a precautionary measure. This proactive step can help prevent potential identity theft and minimize damage from unauthorized access to sensitive information.

Facts based on reporting originally published by CNET.

You may republish this story, in full or in part, if you credit News Central Site and link to it (licence CC BY 4.0). Photos are not included.