March 2025 saw a wave of serious cybersecurity incidents impacting major players across healthcare, cloud infrastructure, social media, and finance. From legacy server vulnerabilities to insider threats, this month’s breaches are a stark reminder: no sector is immune.
Oracle Health Breach: Patient Records Compromised 🏥

What Happened:
A breach at Oracle Health (formerly Cerner) exposed sensitive patient data, with attackers leveraging compromised credentials to infiltrate legacy servers undetected for nearly a month.
Timeline:
January 22 – Initial unauthorized access.
February 20 – Breach discovered and hospitals notified.
Impact:
Hospitals reported stolen records and received extortion threats from a hacker alias “Andrew,” who demanded crypto payments. Criticism mounted over Oracle Health’s vague communications and lack of support.
Key Takeaways:
Hospitals were left to handle HIPAA notifications independently.
Oracle’s delayed and unclear response eroded trust.
The incident underscores the need for stricter credential hygiene, legacy system decommissioning, and faster disclosures.
Oracle Cloud Under Fire: 6 Million Records Allegedly Exposed ☁️
The Flaw:
Attackers reportedly exploited CVE-2021-35587, a critical vulnerability in Oracle Access Manager (CVSS 9.8), gaining access to a treasure trove of sensitive credentials across over 140,000 cloud tenants.
Dispute Over Disclosure:
While Oracle denied any breach, multiple researchers—including Hudson Rock’s Alon Gal and CloudSEK—validated that the leaked credentials were legitimate. As of April 3, 2025, Bloomberg reports that the company informed clients that cybersecurity firm CrowdStrike and the FBI are investigating the incident.
Recommended Action:
Immediately patch Oracle Fusion Middleware components.
Rotate passwords and update security certificates.
Monitor access logs for unusual activity.
The Lesson:
Silence breeds confusion. Transparency, rapid patching, and proactive tenant communication are essential.
Check Point Hack: Source Code and Credentials for Sale? 🛡️
![]()
Claim:
A hacker known as CoreInjection claimed to have breached Check Point’s internal network, stealing proprietary data, network maps, and credentials—offered for 5 BTC.
Company Response:
Check Point admitted to an intrusion but downplayed its severity, calling it a rehash of previously breached data.
Analyst Viewpoint:
Hudson Rock’s Alon Gal noted mixed signals: some leaked material appeared authentic, but the scale remains unclear. The gap between hacker claims and corporate statements shows the need for consistent, evidence-backed communication.
Coinbase: Targeted in Supply Chain Attack

Supply Chain Attack via GitHub Actions:
What Happened:
Between March 10 and March 14, 2025, attackers compromised the GitHub Action tj-actions/changed-files, injecting malicious code designed to exfiltrate CI/CD secrets. Coinbase’s open-source project, agentkit, which utilized this action, was specifically targeted.
Impact:
The attackers obtained a GitHub token with write permissions to the agentkit repository. However, Coinbase’s security team detected the intrusion promptly, preventing any damage to the project or other assets.
Key Takeaways:
Even trusted CI/CD pipelines can be vulnerable to supply chain attacks.
Regular auditing of third-party dependencies is crucial.
Swift detection and response can mitigate potential damage.
These incidents underscore the evolving tactics of cyber adversaries and the importance of robust security measures, both at the organizational and individual levels.
Twitter (X) Insider Leak: 2.8 Billion User Profiles Posted

Twitter (X) Insider Leak: 2.8 Billion User Profiles Posted
The Leak:
Nearly 2.8 billion profiles – about 400GB of user metadata—were posted to Breach Forums. This dwarfs the platform’s active user base, raising suspicions about old, banned, or merged accounts.
Suspected Insider Attack:
A poster by the name of ThinkingOne claimed the leak stemmed from a disgruntled employee post-layoffs, exploiting internal backend vulnerabilities.
Why It Matters:
Even without emails or passwords, the metadata could fuel targeted phishing, impersonation, and account takeovers.
Access Financial Services: Publicly Exposed Customer Data 💳
Incident Overview:
Sensitive personal and financial information from Access Financial Services was found exposed online, accessible to anyone.
Customer Fallout:
The breach triggered outrage, with clients demanding stronger security and oversight. Trust took an immediate hit.
Reminder:
Even a single lapse in data handling can undo years of brand credibility, especially in finance.
StreamElements: Third-Party Breach Exposes Creator Data 🎥
What Happened:
On March 28, popular creator tools platform StreamElements disclosed a data breach stemming from a third-party vendor. The announcement followed the leak of internal data by a hacker on a cybercrime forum.
What Was Exposed:
The leaked information included names, email addresses, and payment details tied to content creators who use the platform for monetization and engagement. The breach did not impact StreamElements’ core infrastructure, but the exposed data originated from a service provider with access to customer information.
Company Response:
StreamElements confirmed the breach, stated it was limited in scope, and began notifying affected users. The company has since severed ties with the vendor involved and is working with cybersecurity experts to review its entire third-party ecosystem.
Why It Matters:
For a platform that enables creators to earn a living, trust is essential. Even when the breach isn’t directly within your walls, your brand takes the hit. This incident reinforces the urgent need for stronger third-party risk assessments, especially in fast-growing platforms serving online communities.
Final Thoughts
From healthcare giants to social media empires, March proved that cyber threats continue to evolve, often faster than corporate responses. Transparency, proactive patching, and clear breach playbooks aren’t just best practices—they’re survival strategies.
Stay informed