SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
▣ Breach ORACLE-PEOPLESOFT- 2026-06-11

Oracle PeopleSoft Customers: ShinyHunters Data Theft Extortion

"The ShinyHunters extortion gang has confirmed it is behind an ongoing wave of data theft attacks targeting Oracle PeopleSoft servers, claiming to have stolen data from 300 instances across more than 100 organizations…"

The ShinyHunters extortion gang has confirmed it is behind an ongoing wave of data theft attacks targeting Oracle PeopleSoft servers, claiming to have stolen data from 300 instances across more than 100 organizations. The campaign, first reported by BleepingComputer's Lawrence Abrams on June 10, 2026, hits both cloud and on-premises PeopleSoft customer instances and is already producing live victims, with the University of Nottingham acknowledging a cybersecurity incident and its data appearing on the gang's leak site.

What Happened

BleepingComputer learned of widespread data theft attacks striking Oracle PeopleSoft customers across both cloud and on-premises deployments. Affected organizations began receiving extortion demands signed by ShinyHunters. The threat actor subsequently confirmed to BleepingComputer that it carried out the attacks, claiming to have compromised 300 separate PeopleSoft instances spanning over 100 distinct organizations.

PeopleSoft is an enterprise business software suite that large organizations rely on to run human resources, payroll, finance, supply chain management, procurement, and student administration. Compromise of these systems exposes some of the most sensitive operational and personal data an organization holds.

According to the threat actor, the majority of impacted organizations sit in the education sector, and many had been previously extorted by the same group. The actor also claimed an initial objective of breaching an FBI portal running PeopleSoft in order to "publish a statement and set the record straight on some misinformation," but said that particular attempt failed and access was never obtained.

What Was Taken

ShinyHunters claims to have exfiltrated data from 300 PeopleSoft instances across more than 100 organizations. Given PeopleSoft's role as the backbone for HR, payroll, finance, and student records, the stolen data likely includes employee and student personally identifiable information, payroll and financial records, procurement details, and supply chain data.

The University of Nottingham is named as a confirmed victim, with the gang stating its data has already been published to the ShinyHunters data leak site. The University issued a statement the same day acknowledging it suffered a cybersecurity incident, corroborating the threat actor's claims.

Why It Matters

This is a supply-side enterprise software incident with broad downstream impact. A single class of vulnerable application, deployed across hundreds of organizations, gives the attacker a repeatable path into high-value data without bespoke targeting of each victim. The heavy concentration in the education sector, much of it organizations previously extorted, shows an actor returning to known-soft targets and monetizing the same victims more than once.

The mix of cloud and on-premises exposure means customers cannot assume a managed environment shields them. With Oracle yet to publicly confirm or disclose details, defenders are operating ahead of vendor guidance and must act on threat intelligence rather than an official advisory.

The Attack Technique

ShinyHunters states it is using a "gadget chain" combining old vulnerabilities with at least one zero-day to compromise PeopleSoft instances. Notably, the actor admits the attack does not succeed against all systems and believes exploitation success depends on how a given instance is configured, suggesting hardening and configuration choices materially affect exposure.

BleepingComputer asked Oracle this morning whether it is aware of a PeopleSoft zero-day being exploited in data theft attacks but had not received a reply. Separately, cybersecurity researcher "Michael R" discovered several exposed online directories tied to the campaign. The researcher reported that ShinyHunters, or a group impersonating them, left directories revealing ongoing targeting of PeopleSoft environments, along with staging materials including MeshCentral agents and a defacement and credential spraying toolkit.

What Organizations Should Do

  1. Inventory every PeopleSoft instance, both cloud and on-premises, and treat all of them as potentially exposed until proven otherwise.
  2. Apply all available Oracle PeopleSoft security patches immediately and monitor Oracle channels for an emergency advisory addressing the reported zero-day.
  3. Audit instance configurations, since the attacker indicates that exploitation success hinges on how each instance is set up; remove unnecessary internet exposure and tighten access controls.
  4. Hunt for indicators of compromise, including unauthorized MeshCentral agents, unexpected remote management tooling, defacement artifacts, and signs of credential spraying.
  5. Reset and rotate credentials for PeopleSoft accounts and any connected service or admin accounts, and enforce multi-factor authentication.
  6. Prepare incident response and breach notification plans now, given the likelihood of HR, payroll, and student data exposure, and watch the ShinyHunters leak site for organizational data.

Sources: Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks