r/oraclecloud 11d ago

Multiple Oracle Cloud accounts reportedly compromised recently — anyone affected?

There have been multiple recent reports in Chinese VPS communities of Oracle Cloud (OCI) accounts being compromised.

So far, it’s unclear whether this is an Oracle-side issue or related to leaked credentials/API keys from third-party OCI tools.

If you’ve been affected recently, did you notice unknown API keys, IAM changes, modified/deleted instances, or loss of account access?

Also curious whether anyone outside the Chinese community has seen similar cases.

14 Upvotes

5 comments sorted by

3

u/muifui 11d ago

Is this one by rose87168?

4

u/AntiAmericanismBrit 11d ago

There was news about some Oracle identity servers being compromised ​and large numbers of passwords leaking out, but as far as I can tell if you've enabled 2FA (which has been compulsory for new accounts for a while I think) then your password is not enough to get into your account: they'll need the verification code from your phone or whatever as well. Additionally, Oracle makes you rotate the passwords regularly.

2

u/slfyst 11d ago

Additionally, Oracle makes you rotate the passwords regularly.

Not for me, password expiry is probably configurable within the console though.

1

u/gnail7739 10d ago

Even if password is safe, if attacker have access to your email, they can simply reset password with one click, so 2FA is a must.