Hundreds of computer systems breached at Oracle, including the customer service portal for its MICROS POS CC payment service; Oracle prompts password resets
Oracle's Micros Payment Systems Hacked Eduard Kovacs / SecurityWeek : Cybercrime Gang Suspected in Attack on Oracle PoS Division Finextra Research Headlines : Hackers hit Oracle Micros POS unit Duncan Riley / SiliconANGLE : Hackers compromise Oracle's MICROS point-of-sale division, steal passwords Zeljka Zorz / Help Net Security : Oracle-owned MICROS PoS systems vendor breached Jon Fingas / Engadget : Oracle data breach opened credit card payment systems to attack Shaun Nichols / The Register : Big Red alert: Oracle's MICROS payment terminal biz hacked Robert Hackett / Fortune : Oracle's Data Breach May Explain Spate of Retail Hacks Laura Hautala / CNET : Hackers infect Oracle's credit card reading machines Catalin Cimpanu / Softpedia News : Oracle MICROS Security Breach Has Ties to Carbanak Gang Chris Mills / BGR : Security breach at Oracle could affect hundreds of thousands of businesses William Turton / Gizmodo : Looks Like a Russian Cybergang Hacked Into One of the World's Largest Payment Systems Troy Wolverton / SiliconBeat : Report: Security breach at Oracle's Micros unit could affect consumers Chris Morran / Consumerist : Cybercriminals Breach Computers For Massive Point-Of-Sale Payment System Eric Abent / SlashGear : Oracle hack could impact payments for hundreds of thousands of businesses Elizabeth Weise / USA Today : Network of 330,000 cash registers is hacked Nate Swanner / The Next Web : Popular point-of-sale system MICROS suffers data breach and nobody knows how bad it is Martyn Williams / ITworld.com : Hackers hit Oracle's Micros payment systems division Zack Whittaker / ZDNet : Oracle investigating data breach at Micros point-of-sale division Dan Goodin / Ars Technica : Oracle-owned point-of-sale service suffers from malware attack Tweets: Shira Ovide / @shiraovide : Wonder if Larry Ellison will stop talking about how Oracle databases have never been hacked? http://krebsonsecurity.com/...
Context & Ripple Effects
The 2016 MICROS breach now reads as the opening entry in a decade-long pattern: attackers repeatedly reaching Oracle's customer-facing and back-office software rather than its databases. Reports at the time tied the intrusion of hundreds of systems — including the customer support portal whose compromise Oracle initially downplayed in later incidents — to the Carbanak gang, though attribution stayed unconfirmed.
What followed validates why this story matters: hackers later hit Oracle's Cerner servers and stole patient data for extortion (the Cerner breach under FBI investigation), stole old login credentials from cloud clients, and exploited an E-Business Suite vulnerability that Google's Mandiant attributed to the Clop group. The MICROS incident established the playbook — compromise the vendor's support channel, reach every merchant behind it.
First-order effects
- Merchants running MICROS point-of-sale terminals had to reset passwords on Oracle's prompt, since the breached customer service portal sat inside the payment-card processing chain they depend on.
- Oracle's support organization became the immediate incident surface: hundreds of internal systems were exposed, shifting remediation from merchants to Oracle's own credential hygiene.
Second-order effects
- Retailers relying on vendor-operated payment support portals faced pressure to treat those channels as attack vectors, forcing managed-service providers and POS rivals to defend their own remote-access practices.
- The suspected Carbanak involvement — a gang known for targeting financial infrastructure — pushed card networks and acquirers to scrutinize how POS vendors' support tools connect to live payment terminals.
Third-order effects
- If the pattern holds, enterprise software vendors become the structural chokepoint for attacks on their entire customer base — a trajectory the corpus confirms with the Cerner extortion, the cloud credential theft, Clop's E-Business Suite exploitation, and ShinyHunters' claimed breaches of over a hundred PeopleSoft users.
- Repeated vendor-side incidents point toward regulators and enterprise buyers demanding faster patching and independent breach confirmation from software suppliers, rather than trusting vendor denials.
The trend: Enterprise software vendors are becoming the preferred entry point for financially motivated hacking groups, with each Oracle division — POS, health records, cloud, ERP — serving as a lever into thousands of downstream customers.