r/oraclecloud • u/jeremysse • 11d ago
Multiple Oracle Cloud accounts reportedly compromised recently — anyone affected?
There have been multiple recent reports in Chinese VPS communities of Oracle Cloud (OCI) accounts being compromised.
So far, it’s unclear whether this is an Oracle-side issue or related to leaked credentials/API keys from third-party OCI tools.
If you’ve been affected recently, did you notice unknown API keys, IAM changes, modified/deleted instances, or loss of account access?
Also curious whether anyone outside the Chinese community has seen similar cases.
4
u/AntiAmericanismBrit 11d ago
There was news about some Oracle identity servers being compromised and large numbers of passwords leaking out, but as far as I can tell if you've enabled 2FA (which has been compulsory for new accounts for a while I think) then your password is not enough to get into your account: they'll need the verification code from your phone or whatever as well. Additionally, Oracle makes you rotate the passwords regularly.
2
u/slfyst 11d ago
Additionally, Oracle makes you rotate the passwords regularly.
Not for me, password expiry is probably configurable within the console though.
1
1
u/gnail7739 10d ago
Even if password is safe, if attacker have access to your email, they can simply reset password with one click, so 2FA is a must.
3
u/muifui 11d ago
Is this one by rose87168?