Last Update: 08/01/2026 at 12:00 PM EST

ShinyHunters targets Oracle PeopleSoft servers in data theft attacks

Coverage from SecurityWeek, BleepingComputer, and others

Articles

10

Active Days

155

The Topic

ShinyHunters targets Oracle PeopleSoft servers in data theft attacks topic image

ShinyHunters-linked attackers exploited a critical Oracle PeopleSoft PeopleTools vulnerability, CVE-2026-35273, to target cloud and on-premises environments and steal organizational data. Google Threat Intelligence Group and Mandiant observed malicious activity affecting more than 100 potentially vulnerable organizations, with higher education disproportionately represented, while Oracle issued emergency mitigations for affected PeopleTools versions. The scale of exposed data, uncertainty around individual victim impact, and extortion-driven leak activity make rapid investigation and access restriction important for PeopleSoft operators.

First Article: 02/24/26

Latest Article: 07/28/26

Summary

  • CVE-2026-35273 affects Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 and enables unauthenticated remote code execution.
  • Google Threat Intelligence Group and Mandiant observed malicious activity from May 27 through June 9 and notified more than 100 organizations with potentially vulnerable endpoints.
  • ShinyHunters claimed data theft from about 300 PeopleSoft instances across more than 100 organizations, but the full victim list and impact remain unconfirmed.
  • Higher education accounted for 68 percent of organizations identified in Google-linked reporting, and the University of Nottingham acknowledged a cybersecurity incident.
  • Reportedly exposed data includes HR, payroll, student, banking, tax, and medical records, although some disclosures remain attacker claims under investigation.
  • Oracle released emergency mitigations and urged immediate action while patch availability and exploitation details remained partly unclear.
  • Recommended response measures include restricting external access, reviewing access and outbound firewall logs, and searching for suspicious JavaServer Pages files and related artifacts.

History

This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.

Featured

Timeline: 155 Days

Feb 24Mar 24Apr 21Jun 2Jun 30Jul 28

Additional Articles

⭐⭐⭐⭐⭐

The Register / Jessica Lyons06-15-2026
ShinyHunters claimed Council of Europe data theft in connection with Oracle PeopleSoft CVE-2026-35273, while Google reported related exploitation affecting 100+ organizations.
Govtech06-15-2026
Google Threat Intelligence Group and Mandiant reported a ShinyHunters compromise of Oracle PeopleSoft between May 27 and June 9, with Oracle issuing a June 10 security alert.
CISO Platform / Pritha Aash07-27-2026
ShinyHunters claimed an Ernst and Young breach on July 27, 2026, after EY disclosed third-party service platform compromise exposing client tax records.
HackRead07-28-2026
ShinyHunters claimed a 2026 data breach and extortion effort against Ernst & Young, after EY detected unauthorized access to a third-party IT platform used for tax work.

⭐⭐⭐

BleepingComputer / Lawrence Abrams06-11-2026
Oracle warned about CVE-2026-35273 in PeopleSoft PeopleTools, which enables unauthenticated remote code execution and was reportedly exploited by ShinyHunters in data theft attacks.
BleepingComputer / Sergiu Gatlan02-24-2026
Odido disclosed a data breach on February 12 in the Netherlands affecting millions of customers.
Infosecurity Magazine05-11-2026
HaveIBeenPwned reported a ShinyHunters campaign tied to stolen Anodot tokens exposed Zara support ticket and Canvas user data across multiple countries in April 2026.