A breach at an online service operated by Helsingin Uusyrityskeskus exposed usernames and passwords stored in plaintext, allowing anyone who obtained the data to use the credentials immediately without cracking hashes. The affected platform, used to create business plans, may also have exposed sensitive information entered into those plans. Finland’s cybersecurity authorities said the leaked data was not known to be publicly available at the time, but assessed it as likely to have circulated among cybercriminals, and the web service was temporarily shut down.
Separately, public claims alleged that Oracle cloud services had been breached and large volumes of data stolen, although Oracle denied that Oracle Cloud itself was compromised and inconsistencies in the attacker’s samples cast doubt on the claims. Even with that uncertainty, CISA warned of a possible leak tied to an older Oracle cloud environment and said exposed credentials could create serious downstream risk for organizations and users, especially where passwords, tokens, or encryption keys are hardcoded in scripts and automation. Authorities urged organizations to review and rotate credentials, enforce phishing-resistant MFA, monitor for suspicious logins, and strengthen password hygiene and user awareness.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
CISA published guidance related to a potential security incident in an outdated Oracle cloud environment, warning that leaked credentials could pose serious risks to organizations and users. The agency recommended credential review and rotation, phishing-resistant MFA, monitoring for suspicious logins, and improved password hygiene and user awareness.
After the breach claims became public, Oracle stated that Oracle Cloud had not been compromised. The reporting nonetheless raised concern that any incident might instead involve an older Oracle service or legacy cloud environment.
In March 2025, public claims surfaced alleging that Oracle's cloud services had been breached and that a large volume of data had been stolen. Reported inconsistencies and attacker-provided samples cast doubt on whether the claims accurately described a compromise of Oracle Cloud itself.
In response to the breach, Helsingin Uusyrityskeskus temporarily shut down the compromised web service intended for creating business plans. Authorities assessed that while the leaked data was not known to be publicly available online, it had likely circulated among cybercriminals.
A data breach affecting an online service operated by Helsingin Uusyrityskeskus exposed usernames and passwords stored in plaintext, along with possible business plan data entered by users. Because the passwords were not hashed, anyone obtaining the stolen data could immediately use the credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.