Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Oracle Cloud

Oracle Cloud Vendor Cyber Rating & Cyber Score

oracle.com

Thanks to exceptional people, we lead the market in autonomous, cloud, and applications technologies.


Oracle Cloud A.I CyberSecurity Scoring

Oracle Cloud
Company Information
Website:https://www.oracle.com/cloud/
Employees number:2
Number of followers:180,059
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:oracle.com
Oracle Cloud Risk Score (AI oriented)
Between 650 and 699
logo
Oracle CloudIT Services and IT Consulting
Updated:
01/04/2026
671/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Oracle Cloud Global Score (TPRM)
xxxx
logo
Oracle CloudIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Oracle Cloud
Oracle CloudWeak
Current Score
671B (WEAK)
01000
3 incidents
-21 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
675Before Incident
MAY 2026
673Before Incident
APRIL 2026
672Before Incident
MARCH 2026
670Before Incident
FEBRUARY 2026
688Before Incident
JANUARY 2026
687Before Incident
DECEMBER 2025
685Before Incident
Cyber Attack
26 Dec 2025Oracle Cloud
Oracle Cloud, Azure and AWS: TeamPCP Turns Cloud Infrastructure into Crime Bots

TeamPCP Exploits Cloud Misconfigurations in Large-Scale Cybercrime Operation

664After Incident
CRITICAL-21
AMAORAMIC1770695748
TeamPCP Exploits Cloud Misconfigurations in Large-Scale Cybercrime Operation A threat actor known as TeamPCP (also operating under aliases like PCPcat and ShellForce) is conducting automated, worm-like attacks on misconfigured and exposed cloud management services, compromising at least 60,000 servers worldwide since late December. The group’s campaign primarily targets Azure (60% of attacks), AWS (37%), and Google and Oracle cloud environments, exploiting well-documented vulnerabilities and misconfigurations rather than developing new attack methods. TeamPCP’s operations involve scanning for exposed Docker APIs, Kubernetes clusters, Ray dashboards, and systems with leaked secrets (such as `.env` files). Once inside, the group deploys malicious Python and Shell scripts to install proxies, tunneling software, and persistence mechanisms, effectively converting compromised infrastructure into a self-propagating botnet. A key tool in their arsenal is the React2Shell vulnerability (CVE-2025-29927), which allows remote command execution and data exfiltration. The group monetizes its attacks through multiple revenue streams, including: - Cryptocurrency mining using hijacked compute resources. - Data theft and extortion, with stolen records including personal IDs, employment records, and résumés published on a leak site operated by an affiliate, ShellForce. - Selling access to compromised systems for use as proxies or command-and-control infrastructure. - Ransomware deployment, leveraging infected systems as launchpads for further attacks. Notably, TeamPCP has targeted JobsGO, a Vietnamese recruitment platform, exfiltrating over two million records containing sensitive personal and professional data. Most victims are located in South Korea, Canada, the U.S., Serbia, and the UAE, with stolen information often used for phishing, impersonation, or account takeovers. Despite its sophistication, TeamPCP’s techniques are not novel the group relies on automated exploitation of known vulnerabilities and recycled tooling. Security firm Flare warns that the threat actor’s strength lies in its large-scale automation, turning exposed cloud infrastructure into a distributed criminal ecosystem. The group also maintains a Telegram channel (launched in November, with ~700 members) for updates and reputation-building, though researchers suggest it may have operated under previous aliases. The campaign underscores the risks of unsecured cloud control planes, leaked credentials, and poor access controls, as TeamPCP continues to industrialize existing attack vectors with alarming efficiency.
INCIDENT DETAILS -
TYPE
Cloud Misconfiguration ExploitationBotnetData TheftRansomware
MOTIVATION
Financial gainData extortionCryptocurrency miningSelling access to compromised systems
IMPACT
Data Compromised: Over two million records (personal IDs, employment records, résumés)Systems Affected: 60,000+ servers worldwideOperational Impact: Compromised infrastructure converted into a botnet for further attacksIdentity Theft Risk: High (personal and professional data used for phishing, impersonation, or account takeovers)
DATA BREACH
Personal IDsEmployment recordsRésumésNumber Of Records Exposed: Over two millionSensitivity Of Data: High (personally identifiable and professional information)
DECEMBER 2025
706Before Incident
Cyber Attack
19 Dec 2025Oracle Cloud
Cloudflare: Aisuru botnet sets new record with 31.4 Tbps DDoS attack

Record-Breaking DDoS Attack by Aisuru/Kimwolf Botnet Peaks at 31.4 Tbps

685After Incident
CRITICAL-21
CLO1769705152
Record-Breaking DDoS Attack by Aisuru/Kimwolf Botnet Peaks at 31.4 Tbps On December 19, Cloudflare mitigated a historic distributed denial-of-service (DDoS) attack launched by the Aisuru (also known as Kimwolf) botnet, reaching an unprecedented 31.4 Tbps and 200 million requests per second (rps). The campaign, dubbed "The Night Before Christmas," targeted telecommunications providers, IT organizations, and Cloudflare’s own infrastructure with hyper-volumetric HTTP and Layer 4 DDoS attacks. This attack surpassed Aisuru’s previous record of 29.7 Tbps, set earlier, and another Microsoft-attributed assault peaking at 15.72 Tbps from 500,000 IP addresses. Over 90% of the attacks in the campaign peaked between 1-5 Tbps, with most lasting 1-2 minutes. Despite their scale, Cloudflare’s automated systems detected and mitigated them without triggering internal alerts. The botnet’s power stems from compromised IoT devices and routers, though the December attacks primarily originated from Android TVs. Cloudflare’s 2025 Q4 DDoS Threat Report revealed a 121% year-over-year increase in DDoS attacks, with 47.1 million incidents recorded in 2025 averaging 5,376 attacks per hour. Network-layer attacks dominated (73%), while HTTP-based assaults made up the remainder. The most targeted industries included telecommunications, IT services, gambling, and gaming, with China, Hong Kong, Germany, Brazil, and the U.S. bearing the brunt of attacks. Bangladesh was the largest source of attacks, followed by Ecuador, Indonesia, and Argentina, while Russia dropped to 10th place. The report also noted a 600% increase in network-layer attacks exceeding 100 million packets per second (Mpps) and a 65% quarter-over-quarter rise in attacks over 1 Tbps. Over 71.5% of HTTP DDoS attacks were linked to known botnets.
INCIDENT DETAILS -
TYPE
DDoS
IMPACT
Telecommunications providersIT organizationsCloudflare infrastructureOperational Impact: Automated mitigation without triggering internal alerts
NOVEMBER 2025
706Before Incident
OCTOBER 2025
705Before Incident
SEPTEMBER 2025
704Before Incident
AUGUST 2025
703Before Incident
JULY 2025
702Before Incident
JUNE 2021
748Before Incident
Breach
16 Jun 2021Oracle Cloud
Oracle Cloud

Cyberattack on Oracle Cloud by 'rose87168'

623After Incident
CRITICAL-125
ORA615032225
The cyberattack on Oracle Cloud orchestrated by 'rose87168' led to the theft of 6 million records potentially affecting over 140,000 tenants. Exfiltrated data includes sensitive JKS files, encrypted SSO passwords, key files, and JPS keys. This information is now sold on dark web forums. The breach, exploiting CVE-2021-35587, poses risks of unauthorized access and corporate espionage given the type of data stolen. Oracle's compromised subdomain and vulnerable software version highlight security gaps and raise concerns of lateral movement within the cloud environment.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Unauthorized accessCorporate espionage
IMPACT
JKS filesEncrypted SSO passwordsKey filesJPS keys
DATA BREACH
JKS filesEncrypted SSO passwordsKey filesJPS keysNumber Of Records Exposed: 6 millionSensitivity Of Data: HighData Exfiltration: YesData Encryption: YesJKS filesSSO passwordsKey filesJPS keys

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Oracle Cloud ?
?
What was Oracle Cloud's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Oracle Cloud's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Oracle Cloud's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Oracle Cloud's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Oracle Cloud's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Oracle Cloud's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Oracle Cloud's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Oracle Cloud's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Oracle Cloud's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Oracle Cloud's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Oracle Cloud's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Oracle Cloud's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Oracle Cloud ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Oracle Cloud's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Oracle Cloud Cyber Scoring History | Rankiteo