Security3 publishersIndependently confirmed2 min readPublished
Nearly 20 million people hit by Oracle Health's legacy Cerner breach, Texas report says
Texas's attorney general puts the breach of Oracle Health's legacy Cerner systems at nearly 20 million people, according to Bloomberg. Oracle has not confirmed the figure, far above the counts in earlier state filings and patient notices.
The Watch · Security desk

What happened
- Oracle told customers the attacker used stolen customer credentials to reach the server sometime after January 22, 2025, and copied data to a remote server.
- Filings with Oregon regulators date the breach from January 22 through April 1, 2025, and give February 20, 2025, as the discovery date.
- A sample letter Cerner filed in California says exposed data may include names, Social Security numbers, diagnoses, medicines, test results and images.
- Sources told BleepingComputer that a lone actor known as 'Andrew', with no claimed tie to an established ransomware or extortion gang, ran the extortion against hospitals.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Hospitals that hold Cerner logins for legacy systems own part of this attack path, because the credentials the attacker used belonged to a customer.
- contradiction The reported total is about six times the three published state counts combined. Per-state filings cannot size this breach until Oracle states a national number.
- precedent If the lone-actor account holds, one person with stolen credentials and no gang behind them reached medical records at this scale. The record ties the intrusion to no wider campaign against EHR vendors.
Oracle began alerting healthcare customers in March 2025 [3]. Its notice said: "We are writing to inform you that, on or around February 20, 2025, we became aware of a cybersecurity event involving unauthorized access to some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud" [4]. Cerner became part of Oracle in June 2022, in a deal that valued it at roughly $28.3 billion [9]. On January 22, 2025, the earliest date in Oracle's account, the data was still on that legacy server, more than two and a half years after the deal [10][18].
By Oracle's own dates, 29 days separate the earliest possible access from the company becoming aware of it [14]. The breach window in the Oregon filings closes 40 days after that discovery date [15].
The smaller counts are state by state. Cerner's entry on the Texas attorney general's breach portal, published October 2, lists 2,992,244 Texans [11]. Notices filed in South Carolina and Washington list roughly 283,000 and 69,000 residents [12]. Those three come to about 3.3 million [16]. The new total comes from a report by the same Texas office that runs that portal, as Bloomberg described it [1][11].
If the figure is confirmed, SecurityWeek wrote, the incident would rank among the biggest US healthcare data breaches ever recorded. By its count, just a few reported incidents were larger, among them the 2024 ransomware attack on Change Healthcare, which hit 192.7 million people [19].
The attacker side is less settled. Oracle's notices and the state filings are public record [4][11]. The name 'Andrew' comes from unnamed sources who spoke to BleepingComputer [5]. The hacker demanded millions of dollars in cryptocurrency to keep the data from being leaked or sold, and set up public websites about the breach to put pressure on victims [6]. The reporting does not say whether any of the data has since been published or sold.
What to watch
- An Oracle or Cerner filing that states a national total of affected individuals, confirming or revising the nearly 20 million figure.
- Any sign that data from the legacy server is published or offered for sale after the extortion demands.
- New state filings that move the combined per-state count closer to the Texas report's total.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The personal and medical information of nearly 20 million people was compromised in a cyberattack on Oracle Health's legacy Cerner systems early last year, Bloomberg reported, citing a report from the Texas attorney general.
ReportedSupportedSource: SecurityWeek, citing Bloomberg, citing a Texas attorney general report2 sources— create a free account to open themView cited source - [2]
Oracle has not made a public statement on the number of affected individuals and declined to comment to Bloomberg.
- [3]
Oracle began alerting healthcare customers in March 2025.
- [4]
"We are writing to inform you that, on or around February 20, 2025, we became aware of a cybersecurity event involving unauthorized access to some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud."
ReportedSupportedSource: Oracle customer notice, as quoted by SecurityWeek2 sources— create a free account to open themView cited source - [5]
Sources told BleepingComputer that extortion attempts against affected hospitals came from an individual threat actor known as 'Andrew', who had not claimed links to any established ransomware or extortion gang.
ReportedSupportedSource: Unnamed sources to BleepingComputer, as reported by SecurityWeek2 sources— create a free account to open themView cited source - [6]
To keep the stolen data from being leaked or sold, the hacker demanded millions of dollars in cryptocurrency and set up public websites about the breach to increase pressure on the victims.
- [7]
"The personal information involved in this incident may have included your name, Social Security number, and information included within patient medical records, such as medical record numbers, doctors, diagnoses, medicines, test results, images, care and treatment."
ReportedSupportedSource: Cerner sample notification letter filed with California regulators, as quoted by SecurityWeek2 sources— create a free account to open themView cited source - [8]
The nearly 20 million figure is far higher than the counts that surfaced in earlier filings and patient notifications.
- [9]
Cerner, an EHR vendor, became part of Oracle in June 2022 after a deal that valued the company at roughly $28.3 billion; the business now operates as Oracle Health.
- [10]
Oracle told customers the available evidence suggested the attacker used stolen customer credentials to access the server sometime after January 22, 2025, and copied data to a remote server.
- [11]
Cerner's entry on the Texas attorney general's data breach portal, published on October 2, lists 2,992,244 affected Texans.
- [12]
Breach notifications filed in South Carolina and Washington list roughly 283,000 and 69,000 affected residents, respectively.
- [13]
Filings with Oregon regulators give January 22 through April 1, 2025, as the dates of the breach, and February 20, 2025, as the discovery date.
- [14]
29 days separate January 22, 2025 (earliest access date) from February 20, 2025 (discovery date).
- [15]
The Oregon breach window ends April 1, 2025, 40 days after the February 20, 2025 discovery date.
- [16]
The Texas, South Carolina and Washington counts together total about 3.3 million people.
- [17]
The nearly 20 million reported total is about six times the combined Texas, South Carolina and Washington counts.
- [18]
The data was still on the legacy server more than two and a half years after Cerner became part of Oracle.
- [19]
If confirmed, the nearly 20 million figure would make the incident one of the largest healthcare data breaches on record in the US; only a handful of reported incidents were bigger, including the 2024 ransomware attack on Change Healthcare, which affected 192.7 million people.
Sources
3 independent publishers whose own reporting we read for this story.
- gizmodo.comOracle Health Data Breach From Last Year Was Reportedly Huge
1 article · October 6, 2026
- Oracle 2025 Health Breach Compromised Data of 20 Million People
news.bloombergtax.com
1 article · October 5, 2026
- securityweek.comOracle Health Data Breach Tally Climbs to Nearly 20 Million
2 articles · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.