ORACLE CORPORATION
ent_019ebd352f055abb3088f290dbeb6c59
Disclosures
3
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
132
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ORACLE CORPORATION
- Normalized
- oracle— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 1Z4GXXU7ZHVWFCD8TV52
- SEC EDGAR CIK
- 0001341439
- Domain
- None on record
Disclosure history (3)newest first
- California State AGas victim2013-07-31
Fidelity Investments, acting as a retirement plan administrator for Oracle Corporation, inadvertently included Oracle employee data in a report viewed by an administrator at another Fidelity client firm on July 10, 2013. The report contained names, Social Security numbers, compensation, and 401(k) details. The unauthorized viewer promptly returned and deleted the report. Fidelity deleted the report from the application and strengthened administrative controls. No misuse was known.
- Massachusetts State AGas victim2007-12-03
Oracle USA, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2007-12-03. 78 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2007-11-28
Oracle USA, Inc. reported a security incident involving a misplaced desktop computer containing personal information of 132 employees and contractors, including 5 in New Hampshire. Data included names, SSNs, addresses, and earnings info. No evidence of misuse was found. Kroll Inc. was engaged to provide one year of credit monitoring.
Supply-chain cascadesreviewed and confirmed
- ORACLE CORPORATION supply-chain incident (2025)2025-11-12 – 2026-07-137 organizations linked
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of ORACLE CORPORATION — not by ORACLE CORPORATION itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Texas State AGvia Cerner Corporation2026-07-07
Cerner Corporation based in Kansas City, Missouri, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-02-20 and reported on 2026-07-07. 2,658,388 Texas residents were affected. 18,565,730 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information. Consumers were notified via U.S. Mail.
- Oregon State AGvia Cerner Corporation2026-07-06
Cerner Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2026-07-06. The breach occurred during 1/22/2025 - 4/1/2025. The breach was discovered on 2/20/2025. 8,329 individuals were affected. Notice was sent on 6/22/2026.
- New Hampshire State AGvia Cerner Corporation2026-06-22
Cerner Corporation submitted a supplemental breach notification to the New Hampshire Attorney General on June 22, 2026, updating the count of affected individuals to 60,247 NH residents. The incident involved unauthorized access to legacy Cerner systems starting January 22, 2025, discovered on March 7, 2025. Affected data included names, SSNs, and PHI. Notification letters were mailed starting July 25, 2025, offering 24 months of credit monitoring.
- Illinois State AGvia Cerner Corporation2026-06-01
CERNER CORPORATION filed a data-breach notice with the Illinois Attorney General in June 2026 (case 26-06-1283). The register records the breach as discovered on February 20, 2025. Personal information types reported: medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGvia Cerner Corporation2025-12-19
Cerner Corporation notified the New Hampshire Attorney General of a security incident involving unauthorized access to PHI on legacy systems. The breach affected approximately 58,823 NH residents, exposing names, SSNs, and medical records. Access occurred as early as Jan 22, 2025; discovered Feb 20, 2025. Notifications began June 13, 2025. Law enforcement requested notification delays. Cerner engaged forensic specialists, reset credentials, and implemented network isolation. Affected individuals received credit monitoring and identity restoration services.
- Illinois State AGvia Cerner Corporation2025-08-01
CERNER CORPORATION filed a data-breach notice with the Illinois Attorney General in August 2025 (case 25-08-346). The register records the breach as discovered on February 20, 2025. Personal information types reported: biometric data, drivers license, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Texas State AGvia Cerner Corporation2025-07-28
Cerner Corporation based in Kansas City, Missouri, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-02-20 and reported on 2025-07-28. 4,082 Texas residents were affected. 1,970,332 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information. Consumers were notified via U.S. Mail.
- California State AGvia Cerner Corporation2025-07-25
Unauthorized third party gained access to legacy Cerner EHR systems beginning at least January 22, 2025, obtaining patient personal information including names, Social Security numbers, medical record numbers, diagnoses, medications, and test results. A healthcare provider (the reporting entity's client) was notified on March 7, 2025. Federal law enforcement requested a delay in patient notification pending investigation. Notices were sent July 25, 2025.
- Nebraska State AGvia Cerner Corporation2025-07-25
Cerner Corporation, an EHR vendor, disclosed a data breach affecting patient information. Unauthorized access occurred on or around January 22, 2025, discovered by Cerner on March 7, 2025. Affected data included names, SSNs, and PHI. Federal law enforcement requested a notification delay. Cerner engaged forensic specialists and law enforcement, offering 24 months of credit monitoring to affected individuals. Notifications were sent in July 2025.
- Oregon State AGvia Cerner Corporation2025-07-25
Cerner Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2025-07-25. The breach occurred during 1/22/2025 - 4/1/2025. The breach was discovered on 2/20/2025. 1,970,332 individuals were affected. Notice was sent on 7/25/2025.