Skip to content
You can now search across every topic, entity and event.What's new
Oracle
OrganisationUS

Oracle

US enterprise software giant that confirmed a 21,000-role AI-driven cut in its FY26 annual report.

Oracle's credit default swap spread reached its 2008 financial-crisis level by 26 July 2026, months after its FY26 filing confirmed AI adoption drove a cut from 162,000 to 141,000 staff to fund a $156bn AI infrastructure programme.

Last refreshed: 27 July 2026 · Appears in 3 active topics

Key Question

Why was an Oracle WebLogic patch from January 2024 still delivering ransomware in June 2026?

Timeline for Oracle

#18 25 Jul
#11 15 Jul

Mentioned in: Oracle EBS gets a 3-day patch clock

Cybersecurity: Threats and Defences
#11 15 Jul
View full timeline →

Background

Oracle began eliminating 20,000 to 30,000 roles on 31 March 2026, roughly 18% of its 162,000-strong global workforce, in the largest single AI-capital reallocation in enterprise software history; its FY26 Form 10-K, filed 22 June, confirmed the toll at 21,000 roles and disclosed severance costs jumping to $1.84bn, while Oracle Cloud Infrastructure was shielded and grew . India absorbed the heaviest share, roughly 12,000 staff terminated by 6am email with no prior warning; US WARN Act filings covered under 4% of those affected .

Founded in 1977 by Larry Ellison, Oracle is the world's second-largest software company by revenue, with dominant positions in enterprise databases, cloud infrastructure and healthcare technology. It is a core partner, alongside OpenAI and SoftBank, in the Stargate data-centre joint venture, whose Dubai facility was struck by Iranian missiles during the March-April 2026 Iran conflict.

Its WebLogic Server middleware remains a long-standing attacker target: a January 2024 patch went unweaponised for 17 months before CISA logged active ransomware exploitation in June 2026, a gap Oracle's E-Business Suite flaw closed to just three days in July . The restructuring is now the template other legacy enterprise vendors follow: cut headcount in service and support roles, redirect capital to compute infrastructure, and route disclosure below the WARN Act's site-level thresholds.

Key Issues
Credit market stress

Its credit spread now signals distress

Oracle's FY26 Form 10-K, filed with the Securities and Exchange Commission on 22 June, confirmed that AI adoption helped drive a workforce reduction from 162,000 to 141,000 employees, the first time the company named AI as a cause in writing. Severance and exit costs jumped from $374 million to $1.84 billion, while Oracle Cloud Infrastructure was shielded from the cuts and grew .

By 26 July, the strain those cuts were meant to relieve showed up on Wall Street: Oracle's credit default swap spread reached its 2008 crisis level, Apollo Global Management's chief economist said, as smaller AI infrastructure lenders posted debt-to-equity ratios rivalling that pre-crisis peak, a market verdict on whether the freed $8-10bn a year genuinely closes Oracle's $20bn AI funding shortfall .

Common Questions

Oracle confirmed AI drove its cuts

Did Oracle confirm exactly how many jobs it cut in 2026?
Yes. Oracle's FY26 Form 10-K, filed with the SEC on 22 June 2026, confirmed a 21,000-role cut (from 162,000 to 141,000 employees) and disclosed severance and exit costs rising from $374 million to $1.84 billion. Oracle Cloud Infrastructure was shielded from the cuts and grew.Source: Oracle FY26 Form 10-K
Is Oracle being investigated for WARN Act violations after its 2026 layoffs?
Law firms were investigating potential violations as of April 2026, but as of 15 May 2026 no litigation has been initiated. The Attorney General's AI Task Force has not filed any enforcement action against Oracle or the other employers — Microsoft, PayPal, and GitLab — who used similar phased or distributed restructuring approaches.Source: Lowdown
Why did Oracle's WARN Act filing cover so few of its laid-off workers?
Oracle filed WARN notices in Washington state (491 positions) and Missouri (539) but filed nothing in Massachusetts despite its Burlington offices. Total filings covered under 4% of the up-to-30,000 affected workforce. The site-based threshold structure and phased implementation allow employers to avoid the 50-worker per-site trigger.Source: Lowdown
Did Oracle file WARN Act notices for all its layoffs?
No. US WARN Act filings covered Washington state (491 workers) and Missouri (539) — fewer than 4% of the up to 30,000 affected workforce. Massachusetts filed nothing despite Oracle's Burlington offices. Law firms are investigating potential violations.Source: Lowdown
Why was Oracle's Dubai data centre attacked by Iran?
The IRGC explicitly named Stargate UAE — the $500 billion joint venture of OpenAI, SoftBank, and Oracle — in a 1 April 2026 military targeting video. Oracle's Dubai data centre had previously been struck by Iranian missiles. The data centre programme is now sited in an active war zone.Source: Lowdown
How many jobs did Oracle cut in 2026 and why?
Oracle eliminated 20,000 to 30,000 employees (roughly 18% of its 162,000 global workforce) from 31 March 2026, freeing an estimated $8-10 billion annually to fund AI data centre spending. India absorbed around 12,000 of the cuts.Source: Lowdown
What is Oracle's role in the Stargate AI programme?
Oracle is a core infrastructure partner in Stargate alongside OpenAI and SoftBank. Its Dubai data centre was targeted in the Iran conflict. The US programme has 1.2 GW operational at Abilene, Texas, against a 10 GW nominal target.Source: Lowdown
How many people did Oracle lay off in 2026?
Oracle cut 20,000 to 30,000 employees starting 31 March 2026 — roughly 18% of its 162,000 global workforce. Around 12,000 were in India, terminated by a 6am email. Annual savings were estimated at $8-10 billion, earmarked for AI data centre spending.Source: Lowdown
Did CISA find a new Oracle vulnerability being exploited in July 2026?
Yes. CISA added CVE-2026-46817, an improper privilege-management flaw in Oracle E-Business Suite, to its Known Exploited Vulnerabilities catalogue on 15 July 2026 with a three-day federal patch Deadline, one of the tightest windows CISA has issued this year.Source: CISA KEV
Is Oracle WebLogic Server still being attacked by hackers?
Yes. CVE-2024-21182 (CVSS 7.5), patched by Oracle in January 2024, was added to CISA's Known Exploited Vulnerabilities catalogue on 1 June 2026 after honeypots recorded active payload delivery including Cobalt Strike beacons and Sodinokibi ransomware — 17 months after the patch shipped.Source: CISA / The Hacker News