ShinyHunters targets Oracle PeopleSoft servers in data-theft attacks against more than 100 organizations

Oracle PeopleSoft customers are being hit in ongoing break-ins and extortion attacks that ShinyHunters says have affected more than 100 organizations and 300 PeopleSoft instances. The campaign reportedly targets both cloud and on-premises PeopleSoft deployments, with the attackers claiming to use a chain of older bugs and at least one zero-day, though no CVE has been confirmed by Oracle. Reported evidence includes extortion notes, exposed attacker tooling, and IP-based indicators of compromise tied to infrastructure previously linked to ShinyHunters.
Why it matters: PeopleSoft is widely used for payroll, HR, finance, procurement, and student systems, so a compromise can expose highly sensitive employee, customer, or student data. Organizations running PeopleSoft should urgently review logs for the listed IPs, investigate possible unauthorized SSH access, and prepare incident response while waiting for Oracle guidance.

Sources

Nissan Employee Data Breached in Oracle PeopleSoft Hack
Eduard Kovacs 2026.06.30 95% relevant
This article confirms Nissan as another victim in the same PeopleSoft zero-day campaign and adds specific breach details: Nissan Americas says attackers exploiting CVE-2026-35273 may have stolen employee SSNs, banking, tax, and payroll-related data affecting current and former employees in the U.S., Canada, Mexico, and Brazil.
Council of Europe hacked in ShinyHunters' PeopleSoft heist
2026.06.15 98% relevant
This article adds a newly identified victim in the same PeopleSoft zero-day campaign: the Council of Europe. It reports the group claims to have stolen 297 GB and 429,000 files including HR, payroll, banking, tax, and medical records, and reiterates the campaign details around CVE-2026-35273 and 100+ affected organizations.
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
Eduard Kovacs 2026.06.12 97% relevant
This source directly advances the same event by tying the campaign to the specific zero-day CVE-2026-35273, confirming Google/Mandiant observed exploitation between May 27 and June 9, noting Oracle issued mitigations without apparent patches, and adding that higher education made up 68% of notified exposed organizations.
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
info@thehackernews.com (The Hacker News) 2026.06.11 96% relevant
This appears to be the same underlying campaign and adds the specific zero-day identifier CVE-2026-35273, ties the activity to breaches at universities, and further clarifies that Oracle PeopleSoft servers are the intrusion path used by ShinyHunters.
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
Lawrence Abrams 2026.06.11 97% relevant
This updates the same underlying incident by identifying the specific flaw exploited as CVE-2026-35273, confirming it is an unauthenticated remote-code-execution zero-day in Oracle PeopleSoft PeopleTools 8.61 and 8.62, and noting Oracle has issued emergency mitigations while a patch is pending.
ShinyHunters claims it hacked 100 orgs by exploiting an Oracle PeopleSoft 0-day
2026.06.11 98% relevant
This article directly updates the same underlying event by identifying the claimed exploit as PeopleSoft zero-day CVE-2026-35273, stating it affects roughly 300 vulnerable instances and more than 100 organizations, and tying the campaign concretely to the University of Nottingham breach and Oracle's out-of-band alert/mitigations.
Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks
Eduard Kovacs 2026.06.11 95% relevant
This source adds Oracle's own out-of-band advisory and mitigation guidance for CVE-2026-35273, a critical unauthenticated RCE in PeopleSoft PeopleTools 8.61 and 8.62, which may be one of the zero-days reportedly used in the same ShinyHunters campaign against 100+ organizations.
Nottingham University data breach affects over 450,000 students
Sergiu Gatlan 2026.06.11 94% relevant
This article adds a named victim in the PeopleSoft-focused ShinyHunters campaign, with victim confirmation of a breach, reported impact of 454,600 people, and details on the types of data exposed from the University of Nottingham's student records system.
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
Lawrence Abrams 2026.06.10 100% relevant
This article appears to be the first clear report establishing a distinct ShinyHunters campaign specifically targeting Oracle PeopleSoft environments across many organizations, with claimed victim count, tactics, and IOCs.
← Back to all stories