Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Nearly 20 million people had their health and personal data compromised in a cyberattack on Oracle Health's legacy Cerner systems, according to a Texas Attorney General report published October 2, 2026. The figure far exceeds initial estimates disclosed in prior months and ranks the incident among the most severe healthcare data breaches in the United States in recent years. Oracle has not issued public statements on the number of individuals affected and declined to comment to Bloomberg.
- The Texas AG estimates nearly 20 million people affected, including nearly 3 million Texas residents
- The attacker used stolen customer credentials to access legacy Cerner servers not yet migrated to Oracle Cloud
- The breach was detected February 20, 2025, but initial access dates to January 22, 2025
- Exposed data includes SSNs, addresses, full medical records, diagnoses, medications, test results, and medical images
Attack Vector: Stolen Credentials and Pre-Acquisition Servers
In a customer notification sent in March 2025, Oracle indicated the event was detected around February 20, 2025. Available evidence suggested the attacker used stolen customer credentials to access the server after January 22, 2025. Data was copied to a remote server.
The servers involved were "old legacy server not yet migrated to the Oracle Cloud," per the company's own notification. This infrastructure was inherited from the Cerner acquisition, which Oracle completed in June 2022 for approximately $28.3 billion. The incomplete migration left systems containing health data on a national scale exposed.
"The incident demonstrates how older infrastructure can remain a material source of third party risk during cloud migration. Even though Oracle says its cloud infrastructure was unaffected, data held on two legacy servers was sufficient to expose information potentially belonging to millions of patients."
Geography of the Impact: From Texas to Washington
The Cerner entry in the Texas AG portal lists 2,992,244 affected Texans. Bloomberg, in its rounded version, reports "about 3 million Texans." Other state notifications complete the picture: approximately 283,000 residents in South Carolina and approximately 69,000 in Washington.
At least 29 hospital and health systems have disclosed they were affected, according to CyPro as cited by CNET. Confirmed customers include Christus Health in Texas and Tri-City Medical Center in California. Oracle Health's federal customers include the Department of Defense and the Department of Veterans Affairs; a VA spokesperson stated the VA was not affected. The potential impact on other federal customers is unclear.
Oregon filings indicate breach dates from January 22 to April 1, 2025. A sample letter filed in California describes the breadth of data: name, Social Security number, medical record numbers, physicians, diagnoses, medications, test results, images, care, and treatment. It is a complete health profile, not merely demographic data.
The Actor and the Extortion: An Individual, Not an Organized Group
According to BleepingComputer sources reported by SecurityWeek, extortion attempts against affected hospitals originated from an individual actor known as "Andrew," with no ties to established ransomware gangs. The hacker demanded millions of dollars in cryptocurrency and created public websites about the breach to increase pressure on victims.
The full identity of "Andrew" has not been confirmed by official investigative sources. It is unknown whether any victim paid, nor the current status of the stolen data: whether it has been published, sold, or is still held. Bloomberg reported the FBI was investigating the breach and allegations that hackers sought to coerce medical companies into paying ransoms.
Comparison with Change Healthcare
If confirmed, the incident would be the second-largest healthcare data breach in the U.S., second only to the 2024 Change Healthcare ransomware attack that affected 192.7 million people. The scale reveals the concentration of risk: a few legacy servers, managed by a dominant vendor, exposed nearly twenty million patients.
The absence of confirmation from Oracle on the total figure leaves room for an interpretive discrepancy: the Texas AG speaks of "almost 20 million," but the vendor remains silent.
What to Do Now
For affected patients, the National Cybersecurity Alliance offered a concrete recommendation: if someone contacts you claiming to represent an insurer or medical provider and asks for sensitive information or payments, hang up and call the provider back at a known, verified number.
The case underscores that cloud migration is not a binary event. The "not yet migrated" servers served as a bridge for the attacker. Oracle Cloud, according to the company itself, was not directly compromised. The distinction is technically correct but strategically incomplete: patients did not suffer a breach of cloud infrastructure, but of their health data stored on systems Oracle had inherited and failed to adequately protect.
Oracle's Silence
Oracle began notifying healthcare customers in March 2025 but has never publicly confirmed the full scope of the incident. The refusal to comment to Bloomberg, combined with the lack of a structured vendor advisory, leaves technical details in the hands of secondary sources and state authorities.
Oracle's silence speaks for itself. The market and regulators may draw their own conclusions.
Frequently Asked Questions
How many people were affected?
Nearly 20 million, according to the Texas Attorney General report of October 2, 2026. Oracle has not confirmed this figure.
What data was exposed?
Name, Social Security number, addresses, medical record numbers, physicians, diagnoses, medications, test results, medical images, care, and treatment.
When did the attack occur?
Initial access dates to January 22, 2025. The breach was detected February 20, 2025. Oregon filings indicate breach dates through April 1, 2025.
Who is the attacker?
BleepingComputer sources indicate an individual known as "Andrew." This has not been confirmed by official investigative sources.
Was Oracle Cloud compromised?
No, according to Oracle. The affected servers were legacy Cerner "not yet migrated to the Oracle Cloud."
Has the information been verified?
The primary source is Bloomberg, reported by SecurityWeek. Bloomberg has a paywall with partial text available. No structured primary vendor advisory with CVE has been identified. Oracle declined to comment.
Information verified against cited sources and current as of publication.
Sources
- https://www.securityweek.com/oracle-health-data-breach-tally-climbs-to-nearly-20-million/
- https://gizmodo.com/oracle-health-data-breach-from-last-year-was-reportedly-huge-2000822029
- https://www.briefs.co/news/texas-ag-oracle-health-data-breach-touched-nearly-20-million/
- https://www.bloomberg.com/news/articles/2026-10-05/oracle-2025-health-breach-compromised-data-of-20-million-people
- https://www.cnet.com/tech/services-and-software/oracle-health-care-data-breach/
- https://podcast.securityweek.com/
- https://www.securityweek.com/contributors/eduard-kovacs/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.