Oracle Health breach tally climbs to nearly 20 million people, report says
Bloomberg, citing a Texas attorney general report, puts the number of people affected by the 2025 attack on legacy Cerner servers at nearly 20 million.
At a glance
- Bloomberg reports nearly 20 million people were affected by the early 2025 attack on Oracle Health's legacy Cerner servers.
- Texas lists 2,992,244 affected residents; South Carolina and Washington report about 283,000 and 69,000.
- Exposed data may include names, Social Security numbers and medical record details such as diagnoses and test results.
- Oracle has not confirmed the total and declined to comment to Bloomberg.
The personal and medical information of nearly 20 million people was compromised in the early 2025 cyberattack on Oracle Health's legacy Cerner systems, Bloomberg reported, citing a report from the Texas attorney general, according to SecurityWeek. The figure is far higher than counts in earlier regulatory filings and patient notices and, if confirmed, would make the incident one of the largest healthcare data breaches on record in the United States.
What happened
Cerner, an electronic health record vendor, became part of Oracle in June 2022 and now operates as Oracle Health. According to SecurityWeek, Oracle said the attacker used stolen customer credentials to access legacy Cerner servers that had not yet been migrated to Oracle Cloud, then copied data to a remote server.
The unauthorized access occurred after January 22, 2025, and Oracle became aware of it on or around February 20, 2025, before starting to notify healthcare customers in March 2025. Filings in Oregon put the breach period at January 22 through April 1, 2025. SecurityWeek notes that sources told BleepingComputer the attacker was an individual known as "Andrew" who did not claim ties to an established ransomware or extortion group. The attacker demanded millions of dollars in cryptocurrency from hospitals to keep the data from being leaked or sold and set up public websites about the breach to raise pressure, the publication said.
Who is affected
The Texas attorney general's data breach portal entry for Cerner, published on October 2, 2026, lists 2,992,244 affected Texans. SecurityWeek reports that about 283,000 people in South Carolina and roughly 69,000 in Washington were also notified. The nearly 20 million total comes from Bloomberg's reporting and has not been confirmed by Oracle, which declined to comment on the number of affected individuals.
A sample notification letter filed with California regulators says the stolen data may include names, Social Security numbers and patient record information such as medical record numbers, doctors, diagnoses, medicines, test results, images and care and treatment details. For comparison, SecurityWeek points out that the 2024 Change Healthcare ransomware attack affected 192.7 million people.
What to do
People who receive a notification letter should follow the guidance it contains and treat unexpected calls, emails or texts referencing their medical care with caution, since detailed health data can make fraud and phishing attempts more convincing. Because Social Security numbers may be involved, affected individuals in the US can consider placing a credit freeze or fraud alert and should review explanation of benefits statements from insurers for services they did not receive. Healthcare organizations still running legacy systems should review credential hygiene and multifactor authentication on externally reachable servers.
Sources
- Oracle Health Data Breach Tally Climbs to Nearly 20 Million — SecurityWeek
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



