THE SecurityWeek report centres on a data breach hitting Oracle Health’s Cerner legacy systems. The Texas attorney general’s office, via Bloomberg, says personal and medical data of nearly 20 million people was compromised in an incident that began in 2025. Oracle has not issued a public statement on the total number affected and declined to comment to Bloomberg.
The breach involved unauthorized access to a legacy Cerner server that had not yet been migrated to Oracle Cloud, with evidence suggesting attackers used stolen customer credentials to access the server and copy data to a remote location. Extortion attempts followed, with the attacker seeking cryptocurrency payments and publicising the breach to increase pressure on victims.
The article sets out a regional breakdown from breach notices and regulator filings. In Texas, 2,992,244 residents are listed as affected; South Carolina and Washington state notifications indicate around 283,000 and 69,000 residents, respectively. Oregon regulator filings cite January 22 to April 1, 2025 as breach dates, with February 20, 2025 recorded as the discovery date.
A California regulator sample letter describes the types of data potentially involved, including names, Social Security numbers, and elements from medical records. If the figure approaches 20 million, the incident would rank among the largest healthcare breaches in the United States, comparable to Change Healthcare’s 192.7 million-record incident in 2024. The article notes that multiple hospitals faced extortion attempts, though it does not allege any ties to a named ransomware group. No CVEs or software version details are provided in the material.