Oracle PeopleSoft customers are being hit in ongoing break-ins and extortion attacks that ShinyHunters says have affected more than 100 organizations and 300 PeopleSoft instances. The campaign reportedly targets both cloud and on-premises PeopleSoft deployments, with the attackers claiming to use a chain of older bugs and at least one zero-day, though no CVE has been confirmed by Oracle. Reported evidence includes extortion notes, exposed attacker tooling, and IP-based indicators of compromise tied to infrastructure previously linked to ShinyHunters.
Eduard Kovacs
2026.06.30
95% relevant
This article confirms Nissan as another victim in the same PeopleSoft zero-day campaign and adds specific breach details: Nissan Americas says attackers exploiting CVE-2026-35273 may have stolen employee SSNs, banking, tax, and payroll-related data affecting current and former employees in the U.S., Canada, Mexico, and Brazil.
2026.06.15
98% relevant
This article adds a newly identified victim in the same PeopleSoft zero-day campaign: the Council of Europe. It reports the group claims to have stolen 297 GB and 429,000 files including HR, payroll, banking, tax, and medical records, and reiterates the campaign details around CVE-2026-35273 and 100+ affected organizations.
Eduard Kovacs
2026.06.12
97% relevant
This source directly advances the same event by tying the campaign to the specific zero-day CVE-2026-35273, confirming Google/Mandiant observed exploitation between May 27 and June 9, noting Oracle issued mitigations without apparent patches, and adding that higher education made up 68% of notified exposed organizations.
info@thehackernews.com (The Hacker News)
2026.06.11
96% relevant
This appears to be the same underlying campaign and adds the specific zero-day identifier CVE-2026-35273, ties the activity to breaches at universities, and further clarifies that Oracle PeopleSoft servers are the intrusion path used by ShinyHunters.
Lawrence Abrams
2026.06.11
97% relevant
This updates the same underlying incident by identifying the specific flaw exploited as CVE-2026-35273, confirming it is an unauthenticated remote-code-execution zero-day in Oracle PeopleSoft PeopleTools 8.61 and 8.62, and noting Oracle has issued emergency mitigations while a patch is pending.
2026.06.11
98% relevant
This article directly updates the same underlying event by identifying the claimed exploit as PeopleSoft zero-day CVE-2026-35273, stating it affects roughly 300 vulnerable instances and more than 100 organizations, and tying the campaign concretely to the University of Nottingham breach and Oracle's out-of-band alert/mitigations.
Eduard Kovacs
2026.06.11
95% relevant
This source adds Oracle's own out-of-band advisory and mitigation guidance for CVE-2026-35273, a critical unauthenticated RCE in PeopleSoft PeopleTools 8.61 and 8.62, which may be one of the zero-days reportedly used in the same ShinyHunters campaign against 100+ organizations.
Sergiu Gatlan
2026.06.11
94% relevant
This article adds a named victim in the PeopleSoft-focused ShinyHunters campaign, with victim confirmation of a breach, reported impact of 454,600 people, and details on the types of data exposed from the University of Nottingham's student records system.
Lawrence Abrams
2026.06.10
100% relevant
This article appears to be the first clear report establishing a distinct ShinyHunters campaign specifically targeting Oracle PeopleSoft environments across many organizations, with claimed victim count, tactics, and IOCs.