Back to News
News · Healthcare & Security

Oracle Health Breach Tally Climbs to Nearly 20 Million

A Texas attorney general report cited by Bloomberg puts the Cerner breach far above earlier counts.

Source: SecurityWeek · October 9, 2026

SecurityWeek reports that Bloomberg, citing a Texas attorney general report, puts the number of people whose personal and medical information was exposed in the attack on Oracle Health's legacy Cerner systems at nearly 20 million, far higher than the counts that surfaced in earlier filings and patient notifications. Oracle has not made a public statement on the number of affected individuals and declined to comment to Bloomberg. The Texas attorney general's own breach portal, updated October 2, lists a much smaller 2,992,244 affected Texans, since the nearly 20 million figure is a broader, national-scale count.

Oracle said it became aware of unauthorized access to Cerner data on an old legacy server not yet migrated to Oracle Cloud around February 20, 2025, and told customers the attacker likely used stolen credentials to copy data to a remote server, with extortion attempts tied to an actor known as "Andrew." If confirmed, the nearly 20 million figure would make this one of the largest healthcare data breaches on record in the US.

Why it matters: legacy systems still holding regulated patient data are a persistent blind spot in healthcare IT, and a single set of stolen credentials on an unmigrated server can scale into one of the largest breaches on record. Inventory and migrate legacy platforms on a firm timeline, and treat credential compromise on any system touching PHI as a board-level risk.