Skip to content
TECH CEO Daily

IDCF Cloud attack hits 495 clients as Oracle Health breach tally nears 20 million

Three incidents disclosed in early October show how one attack on a cloud or health provider spreads to hundreds of clients and keeps costing money for months.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1A ransomware attack on IDC Frontier's IDCF Cloud on October 7 affected 495 companies and local governments, BleepingComputer reported.
  • 2Advantest disclosed on October 6 that personal data was stolen in a February 15 ransomware attack.
  • 3Oracle Health's 2025 breach tally has climbed to nearly 20 million people, according to a Texas attorney general report.

The news

Three ransomware and extortion cases disclosed in early October 2026 show that the cost of a breach rarely stops at the first headline. One is brand new, one is eight months old and one dates to early 2025, and all three hit organizations whose systems or data serve many others.

The newest is in Japan. IDC Frontier, a SoftBank Group company that runs the IDCF Cloud infrastructure service, said a ransomware attack began at 3:40 a.m. local time on October 7 and hit its East Japan Region 1 data center cluster, BleepingComputer reported. The company isolated and shut down affected systems, announced the incident on October 8, and disabled access to its management console in all regions while it checks security. According to BleepingComputer, 495 companies and local governments use the affected service. Separately, Nissui, a Japanese seafood and food company, reported an outage at its logistics subsidiary linked to suspected unauthorized data center access, but BleepingComputer said no connection to the IDCF attack has been confirmed.

The attackers left a message claiming they breached the region in seven minutes, encrypted 225 databases holding 3.6 petabytes of data, reached 239 hypervisors and wiped 554,153 snapshots, BleepingComputer reported. Those are the attackers' claims and have not been confirmed by IDC Frontier, which said it is still investigating the cause and scope. No ransomware group was named in the report.

Separately, Advantest, the Japanese maker of semiconductor test equipment, began notifying people on October 6 that personal information was stolen in a ransomware attack on February 15, 2026, according to BleepingComputer. The company said an unauthorized third party accessed its systems and extracted some data. The exposed fields include contact details, dates of birth, Social Security numbers, passport and driver's license numbers, medical and financial information. Advantest did not say how many people were affected or whether they were customers, employees or partners, and said it had no information that the data had been leaked or misused. It is offering 18 months of identity monitoring through Kroll.

In the United States, SecurityWeek reported on October 8 that the count of people affected by the Oracle Health breach has reached nearly 20 million, a figure from a Texas attorney general report cited by Bloomberg. Oracle (ORCL) has not publicly confirmed the number and declined to comment, SecurityWeek said. According to Oracle's notice to customers, cited by SecurityWeek, the attacker used stolen customer credentials to access legacy Cerner systems not yet moved to Oracle Cloud, starting on or after January 22, 2025, and the breach was discovered on February 20, 2025. Texas filings list 2,992,244 affected residents.

The numbers

IDCF Cloud clients using affected service
495
Data attackers claim they encrypted (unconfirmed)
3.6 PB
Oracle Health breach tally (Texas AG report, via Bloomberg)
Nearly 20 million
Texas residents affected, Oracle Health
2,992,244
Advantest identity monitoring offered
18 months

Why CEOs should care

For CIOs and CISOs, the IDCF case is a test of vendor concentration risk. If a single infrastructure provider went dark, which systems would stop, and is there a recovery copy outside that provider's control? The attackers' claim that they wiped hundreds of thousands of snapshots, if accurate, shows why backups stored in the same cloud are not a full answer. Ask providers how backups are isolated from the management plane and how fast they can restore by region.

For CFOs, Advantest and Oracle Health illustrate the long tail. Notification letters, identity monitoring, legal costs and regulator filings arrive months after the attack, and in Oracle Health's case the affected count kept rising more than a year later. Budget and insurance planning should assume the final bill and the final headcount will be larger than the first estimate.

Boards and procurement teams should review contracts with cloud and health-data vendors: who notifies whom, on what timeline, who pays for notification and monitoring, and whether the vendor must disclose numbers of affected people promptly. Hospitals and health systems using legacy platforms that have not yet migrated should ask how those systems are protected in the meantime.

The bigger picture

The common thread is that the victim is often a provider, and the impact lands on its customers. A cloud operator's outage halts hundreds of clients at once; a health IT vendor's breach exposes patients who never had a direct relationship with it. SecurityWeek noted that among U.S. healthcare breaches only the 2024 Change Healthcare incident, with 192.7 million people affected, was significantly larger than Oracle Health's.

What’s next

Watch for IDC Frontier's findings on the cause and how quickly East Japan Region 1 is restored, whether a ransomware group claims the attack, and whether Oracle confirms a final count for the Oracle Health breach.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

IDC FrontierSoftBankAdvantestOracle HealthRansomware

Earlier coverage of Oracle

All Oracle coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.