ShinyHunters renews exploitation of Oracle PeopleSoft flaw
Google’s Mandiant says ShinyHunters resumed mass exploitation of an Oracle PeopleSoft vulnerability after organizations added defenses but failed to install Oracle’s patch. The activity mainly affected universities during the May 27–June 9 attacks, while the group’s separate claim of accessing FBI data remains unverified.
By DoomRadar · Published on DoomRadar . Updated .
Based on two sources with available article excerpts. Source-linked claims are not independent confirmation.
Event date: The reported PeopleSoft attacks mainly occurred from May 27 through June 9; Mandiant later reported renewed exploitation on September 25. [1]
What happened
Google’s Mandiant said ShinyHunters resumed mass exploitation of a vulnerability in Oracle PeopleSoft software. [1]
References for this detail (1)
- ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google saysthestar.com.my · Recorded source date: Sep 26, 2026, 2:31 AM UTC
Mandiant said the group adapted to defensive guidance and targeted organizations that deployed web-application firewall rules but had not installed Oracle’s security update. [1]
References for this detail (1)
- ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google saysthestar.com.my · Recorded source date: Sep 26, 2026, 2:31 AM UTC
The earlier attacks from May 27 through June 9 mainly affected universities, according to Mandiant. [1]
References for this detail (1)
- ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google saysthestar.com.my · Recorded source date: Sep 26, 2026, 2:31 AM UTC
ShinyHunters alleged that it stole FBI personnel data through the vulnerability, but Reuters said the claim was not corroborated. [1]
References for this detail (1)
- ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google saysthestar.com.my · Recorded source date: Sep 26, 2026, 2:31 AM UTC
Context from the sources
The vulnerability affects enterprise software used for human-resources and other critical organizational functions, increasing the relevance of the campaign beyond a single institution. [1]
Explore the sources and reporting timeline
2 source links · 2 domains
These counts describe the references, not independent confirmations. Different outlets can repeat the same original report.
Source timeline
Oldest to newest among the available source dates, not a chronology of the incident. Article publication dates come from the source; other recorded dates may reflect when a link was found.
- [2] ShinyHunters Alleges it Attacked FBI Job Site, Stole Recordsnatlawreview.com
- [1] ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google saysthestar.com.myReferenced for: detail 1, detail 2, detail 3, detail 4
Questions answered by the reporting
Which organizations were mainly affected by the earlier PeopleSoft attacks?
Mandiant said the May–June attacks mainly affected universities, while the renewed activity targeted organizations that had added firewall rules without applying Oracle’s patch. [1]
What this could mean for you
Organizations using PeopleSoft may face unauthorized access to HR or other enterprise data.
Attackers can exploit the software vulnerability where defensive rules are present but the vendor update is not installed.
Reported basis: [1][2] · The possible effect is interpretation.
Depends on: The organization remains exposed and the vulnerability is exploited successfully.
Employees, applicants and administrators could face disruption or privacy consequences during investigation and recovery.
A compromise of PeopleSoft systems can affect HR records and critical administrative functions.
Reported basis: [1] · The possible effect is interpretation.
Depends on: An exposed organization suffers a confirmed intrusion.
Possible consequences, not a forecast. Their relevance depends on your location and the conditions above.
For your country
Choose a country to check how this event could affect you.
What changes the outlook
Risk increases if…
Further exploitation of unpatched PeopleSoft deployments.
Confirmed compromise of additional organizations or sensitive records.
Pressure eases if…
Organizations install Oracle’s security update rather than relying only on web-application firewall rules.
Additional defensive controls block exploitation across exposed PeopleSoft systems.
Still unclear
The scale and number of organizations affected by the renewed exploitation are not established.
Whether FBI systems or records were accessed remains unverified.
Market implications
Market impact
Sources (2)
References for the reported details. Separate links do not necessarily mean independent confirmation.
Available excerpt
Sept 25 (Reuters) - Google's cybersecurity unit said on Friday that hacking group ShinyHunters has renewed "mass exploitation" of a security flaw in Oracle's PeopleSoft…A short excerpt from our source record; open the original for the full article.
Available excerpt
Ransomware gang ShinyHunters boldly attacked the FBI this week, alleging that it hacked into the FBI’s job site, defaced it, then stole sensitive records of…A short excerpt from our source record; open the original for the full article.
AI-assisted analysis · . Based on linked headlines and available excerpts. Methodology · Report an error.