/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hundreds of computer systems breached at Oracle, including the customer service portal for its MICROS POS CC payment service; Oracle prompts password resets

Oracle's Micros Payment Systems Hacked Eduard Kovacs / SecurityWeek : Cybercrime Gang Suspected in Attack on Oracle PoS Division Finextra Research Headlines : Hackers hit Oracle Micros POS unit Duncan Riley / SiliconANGLE : Hackers compromise Oracle's MICROS point-of-sale division, steal passwords Zeljka Zorz / Help Net Security : Oracle-owned MICROS PoS systems vendor breached Jon Fingas / Engadget : Oracle data breach opened credit card payment systems to attack Shaun Nichols / The Register : Big Red alert: Oracle's MICROS payment terminal biz hacked Robert Hackett / Fortune : Oracle's Data Breach May Explain Spate of Retail Hacks Laura Hautala / CNET : Hackers infect Oracle's credit card reading machines Catalin Cimpanu / Softpedia News : Oracle MICROS Security Breach Has Ties to Carbanak Gang Chris Mills / BGR : Security breach at Oracle could affect hundreds of thousands of businesses William Turton / Gizmodo : Looks Like a Russian Cybergang Hacked Into One of the World's Largest Payment Systems Troy Wolverton / SiliconBeat : Report: Security breach at Oracle's Micros unit could affect consumers Chris Morran / Consumerist : Cybercriminals Breach Computers For Massive Point-Of-Sale Payment System Eric Abent / SlashGear : Oracle hack could impact payments for hundreds of thousands of businesses Elizabeth Weise / USA Today : Network of 330,000 cash registers is hacked Nate Swanner / The Next Web : Popular point-of-sale system MICROS suffers data breach and nobody knows how bad it is Martyn Williams / ITworld.com : Hackers hit Oracle's Micros payment systems division Zack Whittaker / ZDNet : Oracle investigating data breach at Micros point-of-sale division Dan Goodin / Ars Technica : Oracle-owned point-of-sale service suffers from malware attack Tweets: Shira Ovide / @shiraovide : Wonder if Larry Ellison will stop talking about how Oracle databases have never been hacked? http://krebsonsecurity.com/...

Krebs on Security Brian Krebs

Context & Ripple Effects

The 2016 MICROS breach now reads as the opening entry in a decade-long pattern: attackers repeatedly reaching Oracle's customer-facing and back-office software rather than its databases. Reports at the time tied the intrusion of hundreds of systems — including the customer support portal whose compromise Oracle initially downplayed in later incidents — to the Carbanak gang, though attribution stayed unconfirmed.

What followed validates why this story matters: hackers later hit Oracle's Cerner servers and stole patient data for extortion (the Cerner breach under FBI investigation), stole old login credentials from cloud clients, and exploited an E-Business Suite vulnerability that Google's Mandiant attributed to the Clop group. The MICROS incident established the playbook — compromise the vendor's support channel, reach every merchant behind it.

First-order effects

  • Merchants running MICROS point-of-sale terminals had to reset passwords on Oracle's prompt, since the breached customer service portal sat inside the payment-card processing chain they depend on.
  • Oracle's support organization became the immediate incident surface: hundreds of internal systems were exposed, shifting remediation from merchants to Oracle's own credential hygiene.

Second-order effects

  • Retailers relying on vendor-operated payment support portals faced pressure to treat those channels as attack vectors, forcing managed-service providers and POS rivals to defend their own remote-access practices.
  • The suspected Carbanak involvement — a gang known for targeting financial infrastructure — pushed card networks and acquirers to scrutinize how POS vendors' support tools connect to live payment terminals.

Third-order effects

  • If the pattern holds, enterprise software vendors become the structural chokepoint for attacks on their entire customer base — a trajectory the corpus confirms with the Cerner extortion, the cloud credential theft, Clop's E-Business Suite exploitation, and ShinyHunters' claimed breaches of over a hundred PeopleSoft users.
  • Repeated vendor-side incidents point toward regulators and enterprise buyers demanding faster patching and independent breach confirmation from software suppliers, rather than trusting vendor denials.

The trend: Enterprise software vendors are becoming the preferred entry point for financially motivated hacking groups, with each Oracle division — POS, health records, cloud, ERP — serving as a lever into thousands of downstream customers.