How to Respond When Your Identity or Cloud Provider Is Allegedly Breached
Retrospective: this article looks back at events from March 2025, written in 2026 with the benefit of hindsight.
When a credible report claims your identity or cloud provider was breached — but the provider hasn't confirmed it — you still need to act. Here is a practical response plan.
Step 1: Assess credibility quickly
- Who reported it (reputable researchers, threat intelligence firms, news outlets)?
- Is there sample data, and does it include anything recognizable as yours (tenant IDs, domains, user names)?
- What has the provider said, and does it address the specific claims?
Step 2: Take low-cost precautions immediately
Actions that are cheap and safe regardless of the truth:
- Rotate passwords and secrets for accounts and integrations tied to the affected service.
- Revoke and reissue API keys and certificates used with the service.
- Require or re-confirm MFA for affected accounts.
- Review admin accounts for unfamiliar entries.
Step 3: Hunt in your own logs
- Sign-in logs for the provider's service (unusual IPs, times, failed attempts).
- Activity logs for data access and configuration changes.
- Federation and SSO logs if the provider is your identity provider or connected to it.
Step 4: Engage the provider
Open a support case asking specific questions: was our tenant affected, which systems were involved, what indicators should we look for? Request written answers.
Step 5: Involve legal and communications
Assess notification obligations if your data may be involved, and prepare holding statements.
Step 6: Document decisions
Record what you knew, when, and what you did. This protects you if the situation changes.
Step 7: Review dependence
Use the event to evaluate legacy services and contractual notification terms with the provider.
- Oracle Cloud Login Breach Claims (Mar 2025): When the Provider Denies and Customers Rotate Incident Teardowns
- Detecting Cloud SSO Compromise: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: Acting on Unconfirmed Breach Reports CIO Briefings