The ShinyHunters extortion gang has confirmed it is behind an ongoing wave of data-theft attacks against Oracle PeopleSoft servers, claiming to have stolen data from 300 instances spanning more than 100 organizations. The group confirmed its involvement directly to BleepingComputer on June 10, 2026, and has already published stolen Nottingham University data on its leak site. The University has acknowledged a cybersecurity incident in a public statement.
What Happened
Beginning the week of June 9, 2026, both cloud-hosted and on-premises Oracle PeopleSoft customer instances came under coordinated data-theft attacks. Victim organizations began receiving extortion demands signed by ShinyHunters, and the threat actor subsequently confirmed responsibility, claiming compromise of roughly 300 PeopleSoft instances across over 100 organizations. PeopleSoft is a widely deployed enterprise suite used by large institutions to run human resources, payroll, finance, supply chain, procurement, and student administration functions, making any successful breach a high-value data event.
According to the threat actor, the bulk of impacted organizations sit in the education sector, and many had been targeted by ShinyHunters in prior campaigns. The group also disclosed that one of its stated objectives was to breach an FBI portal running PeopleSoft in order to "publish a statement and set the record straight," but said that particular intrusion attempt failed. Oracle had not responded to questions about a possible PeopleSoft zero-day at the time of reporting and has not publicly disclosed the attacks.
What Was Taken
ShinyHunters claims to have exfiltrated data from approximately 300 PeopleSoft instances belonging to more than 100 distinct organizations. Given PeopleSoft's role as a system of record for HR, payroll, and student administration, the exposed data sets likely include highly sensitive personal information such as employee and student records, financial and payroll details, and procurement data. Nottingham University's stolen data has already been posted to the ShinyHunters data leak site, confirming that at least some exfiltrated material is being weaponized for public extortion pressure rather than held privately.
Why It Matters
This campaign demonstrates the systemic risk of a single widely deployed enterprise platform being targeted at scale. Because PeopleSoft underpins core HR, finance, and student systems for large institutions, a workable exploit chain gives an attacker access to the most sensitive data a victim holds. The concentration of victims in the education sector, many of them repeat targets, signals that ShinyHunters is methodically revisiting environments it already understands. The reported attempt against an FBI portal also shows the group is willing to aim at government and law enforcement infrastructure, raising the stakes well beyond ordinary financially motivated extortion.
The Attack Technique
ShinyHunters told BleepingComputer it is using a "gadget chain" combining old and zero-day vulnerabilities to compromise PeopleSoft instances. The group acknowledged the attack does not succeed against every target and believes exploitation success depends on how each instance is configured, suggesting hardened or non-default deployments may resist the chain. Independent corroboration came from researcher "Michael R," who discovered several exposed online directories tied to the operation. Those directories revealed active targeting of PeopleSoft environments along with staging materials, including MeshCentral remote-management agents and defacement and credential-spraying tooling, consistent with post-exploitation persistence and lateral movement.
What Organizations Should Do
- Inventory every PeopleSoft instance, cloud and on-premises, and treat all internet-exposed deployments as priority assets for immediate review.
- Apply all available Oracle PeopleSoft security patches without delay and monitor Oracle advisories closely for emergency fixes addressing the exploited chain.
- Harden instance configurations, since the attacker reports that exploitation success varies by configuration; remove default credentials, restrict exposed services, and place admin interfaces behind VPN or access controls.
- Hunt for indicators of compromise, including unauthorized MeshCentral agents, unexpected remote-management software, defacement artifacts, and signs of credential spraying.
- Reduce attack surface by limiting public internet exposure of PeopleSoft portals and enforcing multi-factor authentication on all administrative and remote-access paths.
- Prepare incident response and notification plans now, including monitoring the ShinyHunters leak site for your organization's data and engaging legal and regulatory teams ahead of any confirmed exposure.
Sources: Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks