Three disclosures this week show how far a single point of failure can reach. Oracle’s healthcare unit confirmed a 2025 intrusion that exposed nearly 20 million people through two legacy servers. Japan convened its first cross-government meeting after a sustained run of corporate attacks. And Denmark found that one private company’s lawful access to the national population register was enough to expose 8.8 million of its 11 million records. Here’s a closer look at this week’s top cybersecurity headlines.

A cyberattack on Oracle Health last year exposed personal data belonging to almost 20 million people, including roughly 3 million Texans, according to a Texas attorney general report. The stolen records cover Social Security numbers, addresses and medical information, with affected providers Christus Health and Tri-City Medical Center saying the data could include names, doctors, diagnoses, medicines and test results. The breach occurred after 22 January 2025, and Oracle alerted some customers that March. The entry point was legacy infrastructure: attackers compromised customer cre dentials, used them to reach two older Cerner servers whose data had not yet migrated to Oracle’s cloud, and copied patient records from them. UK security firm CyPro counts at least 29 hospital and health systems affected, and founding partner Rob McBride noted that older infrastructure remains a material source of third party risk during cloud migration.
Experts advise treating migration as a distinct risk phase rather than a transitional inconvenience. Systems awaiting decommission often sit outside both the old monitoring regime and the new one, and credential-based access to them rarely triggers production-grade alerting.
Source: CNET, Bloomberg Law
Japan’s government convened all ministries and agencies on Thursday in its first coordinated response to a series of attacks on private companies. Cybersecurity minister Toshiharu Furukawa said the government will urge firms to address system vulnerabilities promptly and adopt multifactor authentication, and instructed participants to report leaks to the National Cybersecurity Office for centralised management. The NCO said attacks on private firms began rising in August, that the perpetrators remain unknown, and that countermeasures should assume attackers are using artificial intelligence. The National Police Agency separately confirmed the Qilin ransomware group has hit 53 Japanese companies spanning manufacturing, services, construction, hospitals and schools. Recent disclosures include Times Car at 6.6 million accounts with 1.6 million driver’s licence images, Daiichikosho at 8.72 million records via a subcontractor’s infected computer, Lawson at 2.16 million IDs, and a ransomware attack on SoftBank subsidiary IDC Frontier that disrupted 495 corporate and local government customers.
Experts stress data minimisation alongside defence. Security firm LAC recommends promptly purging records of former members and terminated customers, since Times Car’s exposure included licence images belonging to people who had already closed their accounts.
Source:Jiji Press, The Mainichi, Asahi Shimbun, AsiaTodayy
Denmark’s Central Person Register, the national civil registration system established in 1968, disclosed that attackers obtained the names, addresses and CPR numbers of approximately 8.8 million registered people, living and deceased, from a database holding around 11 million. The attackers did not break in. Under Danish law, private companies with a legitimate interest may query the CPR for information on specific individuals, and the intruders abused one Danish company’s lawful access to run searches. Irregular behaviour was detected on the evening of Friday 2 October, with access traced back to an unspecified point in September. Those registered with name and address protection were not exposed. Minister Christina Egelund called it a deeply serious incident. The CPR administration revoked the company’s access, notified the Danish Data Protection Agency, and opened a police investigation. No threat actor has been named.
Experts note that vendor risk management cannot rest on annual reviews. Huntress and SecurityScorecard both recommend continuous monitoring of third party access patterns, with rate limiting and behavioural baselines to catch unusual search volumes before millions of records leave.
Source: Cybernews, SecurityWeek, IT Pro, Infosecurity Magazine
Three different failures, one shared shape. Oracle’s data sat on servers already scheduled for retirement. Daiichikosho’s 8.72 million records went through a subcontractor’s infected laptop. Denmark’s register was queried with valid credentials belonging to someone else. None of these required breaking a perimeter, because in each case the access already existed.