Cyber & AI intelligence
Wasteland.
Briefs indexed2904
Issues29
Published Mondays07:30 CT
▣ Breach ORACLE-PEOPLESOFT- 2026-09-28

Oracle PeopleSoft Customers: ShinyHunters Bypasses Summer Fixes in Renewed Mass Exploitation

"ShinyHunters, the extortion group Google tracks as UNC6240, has started a second wave of attacks on Oracle PeopleSoft HR and payroll systems. This time it is getting into organizations that thought they had already…"

ShinyHunters, the extortion group Google tracks as UNC6240, has started a second wave of attacks on Oracle PeopleSoft HR and payroll systems. This time it is getting into organizations that thought they had already closed the hole. Google's Mandiant and Threat Intelligence Group reported on Friday, September 25, that the group is again mass-exploiting CVE-2026-35273. That is the critical PeopleSoft flaw it first used as a zero-day between May 27 and June 9. The new wave has compromised "dozens of systems" worldwide in higher education, technology, IT services, healthcare, agriculture, transportation and government, according to reporting by Reuters (via CNA) and CyberInsider. Mandiant has not named any victims. Days before the report, ShinyHunters claimed it had breached the FBI's recruitment portal through PeopleSoft and taken 2TB to 3TB of data. The FBI confirmed it is investigating but has not said how the attackers got in. None of the 8 sources is a primary statement from Oracle, Mandiant or a victim. Mandiant's findings come to us through press reports.

What Happened

The summer wave (May 27 to June 9). ShinyHunters used CVE-2026-35273 to break into PeopleSoft environments, mostly at universities. The Next Web, citing TechCrunch, reported that Mandiant notified more than 100 organizations worldwide, most of them in the United States, and that about two-thirds were universities and colleges. The University of Nottingham was named among them. Mandiant wrote that "several organizations successfully blocked the activity or remediated the vulnerabilities," but others were compromised and had their data published on the ShinyHunters leak site.

Patch timeline: accounts differ. CyberInsider reports that Oracle issued an emergency security update on June 10. The Next Web, writing on June 11, said Oracle had published an advisory but "has not released a patch." Reuters (via CNA) refers to "an update that Oracle issued to patch the vulnerability." A fix clearly exists now, but the sources disagree on exactly when it became available. Oracle did not respond to requests for comment from Reuters or TechCrunch.

The FBI claim (September 21 to 23). ShinyHunters told BleepingComputer and CyberInsider that on the night of Monday, September 21 it used a PeopleSoft remote code execution flaw against apply.fbijobs.gov. It says it then moved laterally into FBI-managed AWS GovCloud infrastructure. The group claims it compromised FBI "Criminal Justice (CJ), HR, Medlink, and more." It defaced the jobs site with its Umbreon logo and the message "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS." Nextgov/FCW reports that the group demanded the FBI retract its May 15 public service announcement about the group's harassment tactics within a week, and said the attack was not financially motivated. On September 23 the FBI said it was "actively and aggressively investigating" and that "the point of breach is still undetermined—whether a third-party or the FBI's enterprise" (Cybersecurity Dive).

The renewed campaign (reported September 25). Mandiant's report came out days after the FBI claim. CyberInsider says Mandiant's observations back up ShinyHunters' statement that it had resumed exploiting PeopleSoft against a wider set of targets.

Zero-day or bypass? Accounts differ. ShinyHunters told BleepingComputer and CyberInsider it was using a new, undisclosed PeopleSoft zero-day. Mandiant, as reported by CyberInsider and Reuters, describes the current campaign as the same CVE-2026-35273 exploited through a firewall bypass. CyberInsider published an FBI screenshot showing a /PSEMHUB/ path on the jobs portal, and that is the same endpoint Mandiant links to CVE-2026-35273. That points toward the known flaw rather than a new one, but no source has confirmed which bug was used against the FBI. BleepingComputer, Reuters and CyberInsider all say they could not independently verify the group's FBI claims.

What Was Taken

PeopleSoft HR and payroll modules usually hold bank account details, tax records and national ID numbers. A compromise can therefore lead directly to identity fraud and payroll diversion.

Why It Matters

The Attack Technique

What Organizations Should Do

  1. Apply Oracle's CVE-2026-35273 update now. If you are relying on a WAF rule or other workaround, treat the system as unpatched. Get written confirmation from IT and from any payroll, benefits or recruiting vendor that runs PeopleSoft for you.
  2. Normalize URLs before WAF inspection. Make sure your WAF decodes percent-encoding before matching rules. Block or alert on any encoded variant of PSEMHUB, such as %50SEMHUB, in any combination of case and encoding.
  3. Hunt for compromise, not just exposure. Search PeopleSoft web roots for unexpected JSP files, especially x.jsp and u.jsp. Review access logs back to at least May 27 for PSEMHUB requests, encoded or not. On Windows hosts, look for unfamiliar executables around 5.2MB.
  4. Contain the blast radius. Limit outbound traffic from PeopleSoft servers. Rotate service and database credentials the application uses. Watch for lateral movement into cloud tenants from ERP hosts.
  5. Harden payroll changes. Stolen bank details are often used to redirect wages. Follow Nissan's lead by allowing direct deposit changes only from corporate networks, and require out-of-band phone confirmation before changing where pay goes (Human Resources Director).
  6. Prepare staff for extortion contact. Brief employees and executives on ShinyHunters' harassment and swatting tactics. Coordinate with law enforcement in advance. Verify any claims about stolen data before responding, since the group has been known to exaggerate.

Sources: Major HR system hacked again as criminals slip past summer ... | ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach | ShinyHunters claims FBI data theft, demands bureau ... | FBI probes cyberattack tied to third-party jobs portal | ShinyHunters claims FBI breach via new Oracle PeopleSoft zero-day... | Google warns ShinyHunters is mass-exploiting Oracle PeopleSoft flaw | ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Googl... | ShinyHunters breached 100+ companies through an unpatched Oracle Pe...