ShinyHunters, the extortion group Google tracks as UNC6240, has started a second wave of attacks on Oracle PeopleSoft HR and payroll systems. This time it is getting into organizations that thought they had already closed the hole. Google's Mandiant and Threat Intelligence Group reported on Friday, September 25, that the group is again mass-exploiting CVE-2026-35273. That is the critical PeopleSoft flaw it first used as a zero-day between May 27 and June 9. The new wave has compromised "dozens of systems" worldwide in higher education, technology, IT services, healthcare, agriculture, transportation and government, according to reporting by Reuters (via CNA) and CyberInsider. Mandiant has not named any victims. Days before the report, ShinyHunters claimed it had breached the FBI's recruitment portal through PeopleSoft and taken 2TB to 3TB of data. The FBI confirmed it is investigating but has not said how the attackers got in. None of the 8 sources is a primary statement from Oracle, Mandiant or a victim. Mandiant's findings come to us through press reports.
What Happened
The summer wave (May 27 to June 9). ShinyHunters used CVE-2026-35273 to break into PeopleSoft environments, mostly at universities. The Next Web, citing TechCrunch, reported that Mandiant notified more than 100 organizations worldwide, most of them in the United States, and that about two-thirds were universities and colleges. The University of Nottingham was named among them. Mandiant wrote that "several organizations successfully blocked the activity or remediated the vulnerabilities," but others were compromised and had their data published on the ShinyHunters leak site.
Patch timeline: accounts differ. CyberInsider reports that Oracle issued an emergency security update on June 10. The Next Web, writing on June 11, said Oracle had published an advisory but "has not released a patch." Reuters (via CNA) refers to "an update that Oracle issued to patch the vulnerability." A fix clearly exists now, but the sources disagree on exactly when it became available. Oracle did not respond to requests for comment from Reuters or TechCrunch.
The FBI claim (September 21 to 23). ShinyHunters told BleepingComputer and CyberInsider that on the night of Monday, September 21 it used a PeopleSoft remote code execution flaw against apply.fbijobs.gov. It says it then moved laterally into FBI-managed AWS GovCloud infrastructure. The group claims it compromised FBI "Criminal Justice (CJ), HR, Medlink, and more." It defaced the jobs site with its Umbreon logo and the message "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS." Nextgov/FCW reports that the group demanded the FBI retract its May 15 public service announcement about the group's harassment tactics within a week, and said the attack was not financially motivated. On September 23 the FBI said it was "actively and aggressively investigating" and that "the point of breach is still undetermined—whether a third-party or the FBI's enterprise" (Cybersecurity Dive).
The renewed campaign (reported September 25). Mandiant's report came out days after the FBI claim. CyberInsider says Mandiant's observations back up ShinyHunters' statement that it had resumed exploiting PeopleSoft against a wider set of targets.
Zero-day or bypass? Accounts differ. ShinyHunters told BleepingComputer and CyberInsider it was using a new, undisclosed PeopleSoft zero-day. Mandiant, as reported by CyberInsider and Reuters, describes the current campaign as the same CVE-2026-35273 exploited through a firewall bypass. CyberInsider published an FBI screenshot showing a /PSEMHUB/ path on the jobs portal, and that is the same endpoint Mandiant links to CVE-2026-35273. That points toward the known flaw rather than a new one, but no source has confirmed which bug was used against the FBI. BleepingComputer, Reuters and CyberInsider all say they could not independently verify the group's FBI claims.
What Was Taken
- Summer wave: A ShinyHunters member told TechCrunch (via The Next Web) that the group took "hundreds of thousands of student records" containing names, home addresses, phone numbers, email addresses, dates of birth, gender, ethnicity, enrollment status, GPA, major and student ID.
- Employers: Human Resources Director reports that Nissan told employees in the US, Canada, Mexico and Brazil that their Social Security numbers and bank details may have been stolen. The same outlet reports that ShinyHunters claimed it took payroll and medical records from the Council of Europe. Neither claim is confirmed by a primary source in this set.
- FBI (claimed): 2TB to 3TB of data, according to the group's statements to BleepingComputer and CyberInsider. The group says this includes PII and health information on current and former FBI employees and "all applicant information." Cybersecurity Dive reports that 404 Media confirmed a sample the group provided contained agents' sensitive personal information. Reuters (via CNA) reports that the group exposed names of some personnel. The FBI has acknowledged only that the group is alleging impact to employee PII.
- Renewed wave: Mandiant has not published what data was taken, or from whom.
PeopleSoft HR and payroll modules usually hold bank account details, tax records and national ID numbers. A compromise can therefore lead directly to identity fraud and payroll diversion.
Why It Matters
- Mitigations are not patches. Mandiant's central finding is that the group adapted to the defensive guidance published after the summer attacks. It went specifically after organizations that deployed WAF rules instead of Oracle's update. Mandiant said workarounds "are not a substitute for patching" (Human Resources Director).
- ERP systems are a high-value target. A single PeopleSoft server holds a workforce's most sensitive identity and financial data, and it also gives attackers a foothold in the internal network.
- Supply chain exposure. The FBI has not ruled out a third-party provider as the entry point. Organizations with outsourced payroll or recruiting should assume their vendors are exposed until proven otherwise.
- Harassment risk to staff. The FBI's May 15 PSA warned that ShinyHunters threatens victims and their families and in some cases uses swatting. According to Cybersecurity Dive, people familiar with the FBI breach told Politico it could enable harassment or stalking of agents. The PSA also warned that the group sometimes exaggerates what it has taken (Nextgov/FCW).
The Attack Technique
- Vulnerability: CVE-2026-35273, CVSS 9.8, exploitable remotely without authentication. The Next Web reports it affects PeopleTools 8.61 and 8.62 and that the summer campaign chained old and zero-day bugs against both cloud and on-premises instances.
- WAF bypass: According to CyberInsider's summary of Mandiant's report, attackers request /%50SEMHUB/ instead of /PSEMHUB/, where %50 is the URL-encoded letter "P". Some WAFs check the raw URL and miss the blocked path. PeopleSoft then decodes the request and processes it normally.
- Post-exploitation: The attackers deploy JSP web shells, including x.jsp and u.jsp, to run commands and upload more tooling. On Windows hosts they also drop a 5.2MB executable (CyberInsider).
- Claimed lateral movement: In the FBI case, the group says it went from RCE on the PeopleSoft host into AWS GovCloud workloads. This is unverified.
What Organizations Should Do
- Apply Oracle's CVE-2026-35273 update now. If you are relying on a WAF rule or other workaround, treat the system as unpatched. Get written confirmation from IT and from any payroll, benefits or recruiting vendor that runs PeopleSoft for you.
- Normalize URLs before WAF inspection. Make sure your WAF decodes percent-encoding before matching rules. Block or alert on any encoded variant of PSEMHUB, such as %50SEMHUB, in any combination of case and encoding.
- Hunt for compromise, not just exposure. Search PeopleSoft web roots for unexpected JSP files, especially x.jsp and u.jsp. Review access logs back to at least May 27 for PSEMHUB requests, encoded or not. On Windows hosts, look for unfamiliar executables around 5.2MB.
- Contain the blast radius. Limit outbound traffic from PeopleSoft servers. Rotate service and database credentials the application uses. Watch for lateral movement into cloud tenants from ERP hosts.
- Harden payroll changes. Stolen bank details are often used to redirect wages. Follow Nissan's lead by allowing direct deposit changes only from corporate networks, and require out-of-band phone confirmation before changing where pay goes (Human Resources Director).
- Prepare staff for extortion contact. Brief employees and executives on ShinyHunters' harassment and swatting tactics. Coordinate with law enforcement in advance. Verify any claims about stolen data before responding, since the group has been known to exaggerate.
Sources: Major HR system hacked again as criminals slip past summer ... | ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach | ShinyHunters claims FBI data theft, demands bureau ... | FBI probes cyberattack tied to third-party jobs portal | ShinyHunters claims FBI breach via new Oracle PeopleSoft zero-day... | Google warns ShinyHunters is mass-exploiting Oracle PeopleSoft flaw | ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Googl... | ShinyHunters breached 100+ companies through an unpatched Oracle Pe...