Entra ID & IdentityHow-To & HardeningRetrospectives

How to Respond When Your Identity or Cloud Provider Is Allegedly Breached

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2025, written in 2026 with the benefit of hindsight.

When a credible report claims your identity or cloud provider was breached — but the provider hasn't confirmed it — you still need to act. Here is a practical response plan.

Step 1: Assess credibility quickly

  • Who reported it (reputable researchers, threat intelligence firms, news outlets)?
  • Is there sample data, and does it include anything recognizable as yours (tenant IDs, domains, user names)?
  • What has the provider said, and does it address the specific claims?

Step 2: Take low-cost precautions immediately

Actions that are cheap and safe regardless of the truth:

  • Rotate passwords and secrets for accounts and integrations tied to the affected service.
  • Revoke and reissue API keys and certificates used with the service.
  • Require or re-confirm MFA for affected accounts.
  • Review admin accounts for unfamiliar entries.

Step 3: Hunt in your own logs

  • Sign-in logs for the provider's service (unusual IPs, times, failed attempts).
  • Activity logs for data access and configuration changes.
  • Federation and SSO logs if the provider is your identity provider or connected to it.

Step 4: Engage the provider

Open a support case asking specific questions: was our tenant affected, which systems were involved, what indicators should we look for? Request written answers.

Step 5: Involve legal and communications

Assess notification obligations if your data may be involved, and prepare holding statements.

Step 6: Document decisions

Record what you knew, when, and what you did. This protects you if the situation changes.

Step 7: Review dependence

Use the event to evaluate legacy services and contractual notification terms with the provider.

respond to cloud provider breachOracle Cloud SSO breach claims2025

More on this story