ShinyHunters targets Oracle PeopleSoft servers in data theft attacks
Coverage from SecurityWeek, BleepingComputer, and others
Articles
10
Active Days
155
The Topic

ShinyHunters-linked attackers exploited a critical Oracle PeopleSoft PeopleTools vulnerability, CVE-2026-35273, to target cloud and on-premises environments and steal organizational data. Google Threat Intelligence Group and Mandiant observed malicious activity affecting more than 100 potentially vulnerable organizations, with higher education disproportionately represented, while Oracle issued emergency mitigations for affected PeopleTools versions. The scale of exposed data, uncertainty around individual victim impact, and extortion-driven leak activity make rapid investigation and access restriction important for PeopleSoft operators.
First Article: 02/24/26
Latest Article: 07/28/26
Summary
- CVE-2026-35273 affects Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 and enables unauthenticated remote code execution.
- Google Threat Intelligence Group and Mandiant observed malicious activity from May 27 through June 9 and notified more than 100 organizations with potentially vulnerable endpoints.
- ShinyHunters claimed data theft from about 300 PeopleSoft instances across more than 100 organizations, but the full victim list and impact remain unconfirmed.
- Higher education accounted for 68 percent of organizations identified in Google-linked reporting, and the University of Nottingham acknowledged a cybersecurity incident.
- Reportedly exposed data includes HR, payroll, student, banking, tax, and medical records, although some disclosures remain attacker claims under investigation.
- Oracle released emergency mitigations and urged immediate action while patch availability and exploitation details remained partly unclear.
- Recommended response measures include restricting external access, reviewing access and outbound firewall logs, and searching for suspicious JavaServer Pages files and related artifacts.
History
This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.
