Cyber & AI intelligence
Wasteland.
Briefs indexed3034
Issues31
Published Mondays07:30 CT
▣ Breach SHINYHUNTERS-PEOPL 2026-10-07

Oracle PeopleSoft Customers: ShinyHunters Mass-Exploits PSEMHUB Flaw After Claimed FBI Breach

"The extortion group ShinyHunters is running a renewed, multi-sector exploitation campaign against Oracle PeopleSoft. The campaign surfaced after the group claimed it breached the FBI through what it called a new…"

The extortion group ShinyHunters is running a renewed, multi-sector exploitation campaign against Oracle PeopleSoft. The campaign surfaced after the group claimed it breached the FBI through what it called a new PeopleSoft zero-day. Mandiant and Google Threat Intelligence Group (GTIG) report web shells deployed on "dozens of systems globally" in higher education, technology, IT services, healthcare, agriculture, transportation and government. The group's FBI claims include 2TB to 3TB of stolen data, which has not been independently verified. One question is still open: is this a new zero-day, or an evolved exploit for CVE-2026-35273, the flaw patched in June? Accounts differ. Oracle has not commented publicly. None of the eight sources behind this brief is a primary vendor advisory or victim statement, so the details below rest on security press reporting and named researchers.

What Happened

The current activity follows an earlier campaign. Between May 27 and June 9, 2026, ShinyHunters (tracked by Google as UNC6240) exploited CVE-2026-35273 as a zero-day. It is a critical missing-authentication flaw in PeopleSoft's Environment Management Hub (PSEMHUB) that allows unauthenticated remote code execution. Oracle patched it on June 10. That wave hit more than 100 PeopleSoft customers, most of them universities, according to SecurityWeek and Exabeam's Steve Povolny. SecurityWeek lists the University of Nottingham, the insurance regulators' association NAIC, and Nissan among the confirmed victims. Povolny says ShinyHunters later stated that the original goal of that wave was an FBI PeopleSoft server, and that the attempt failed.

On September 22, ShinyHunters defaced the FBI jobs portal (apply.fbijobs.gov) with its Umbreon logo and the message "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS." The group told BleepingComputer and CyberInsider that it had found a new PeopleSoft RCE zero-day, used it against the FBI, and then moved laterally into FBI-managed AWS GovCloud infrastructure. Infosecurity Magazine reports that the group presented the attack as retaliation for a May 15 FBI Public Service Announcement (PSA) about its tactics. Infosecurity also suggests the aim may have been to force changes to the PSA rather than to extort money.

The FBI's position has shifted over time, and reports describe it differently: - September 22: The FBI told BleepingComputer it was "aware of claims regarding unauthorized activity affecting FBIjobs.gov" and was investigating. It did not confirm a breach. - Internal memo: The Record cites a memo obtained by the New York Times in which senior officials acknowledged the breach and said they were "operating under the premise that the threat actor is also exfiltrating [personal information] of all F.B.I. employees." - Conflicting accounts of the FBI's statements: CSO Online says the FBI has confirmed the breach without giving details, but also says there has been "no official word" from the FBI or Oracle about PeopleSoft's role. Infosecurity Magazine attributes the PeopleSoft-to-GovCloud account to an FBI spokesperson speaking to 404 Media. Treat FBI attribution of the entry vector as unsettled.

On September 26, Mandiant and GTIG published research showing that ShinyHunters had restarted exploitation of CVE-2026-35273. This time the group used a modified exploit that gets around the WAF-based workarounds many organizations deployed instead of patching.

Law enforcement has also acted. The Dutch National Police arrested one suspected member. About a week later, Reuters reported a second arrest, and this suspect is said to be cooperating with investigators. The two CSO Online pieces describe this second arrest differently: one says the FBI made it, the other places it in Jordan. Analysts quoted by CSO Online downplayed what the arrests mean for the operational threat.

What Was Taken

Why It Matters

PeopleSoft runs HR, payroll, finance, recruiting and student systems across government, higher education, healthcare and large enterprises. A compromised PeopleSoft server therefore exposes some of the most sensitive data an organization holds. The bigger lesson is that workarounds failed. Mandiant says ShinyHunters "adapted to published defensive guidance, targeting organizations that implemented [workarounds] but did not patch." Organizations that treated a WAF rule as their fix in June were exposed by September.

The attribution question changes what defenders need to do. SecurityWeek and SC Media note that the "new zero-day" ShinyHunters claims may be the WAF-bypass variant of CVE-2026-35273 rather than a new bug. Google's report does not mention the FBI and does not identify a previously unknown flaw. If that reading is correct, patching closes the hole. If it is wrong, even fully patched PeopleSoft estates are exposed. With Oracle silent, defenders should plan for the second case.

The Attack Technique

According to Mandiant and GTIG, as reported by SC Media and SecurityWeek:

What Organizations Should Do

  1. Patch CVE-2026-35273 now. Oracle's June 10 fix is the baseline. WAF rules are not a substitute, and this campaign targets organizations that relied on them.
  2. Take PSEMHUB and Integration Broker off the internet. Frank Dickson of Dickson Research says that if a new flaw exists, "the patch is necessary but not sufficient." He advises pulling both components off the public internet and notes that "doing so does not break normal user sessions."
  3. Normalize before matching. Make sure WAF and reverse-proxy rules decode URLs (and handle case variants) before matching paths. Block any decoded request path containing PSEMHUB at the edge.
  4. Hunt for compromise. Search web and WebLogic logs for /%50SEMHUB/ and other encoded PSEMHUB requests going back to at least late May. Sweep PeopleSoft web roots for web shells. Review outbound connections from PeopleSoft hosts.
  5. Limit blast radius. Segment PeopleSoft servers from cloud control planes and other internal services. Rotate credentials and cloud keys that are reachable from PeopleSoft hosts. Watch for unusual bulk exports of HR and applicant data.
  6. Prepare for extortion and harassment. ShinyHunters' pattern is data theft followed by public pressure. Pre-stage notification, legal and executive-protection playbooks, especially where employee PII is held.

Sources: ShinyHunters’ exploitation of a new PeopleSoft zero-day hole threat... | ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach | ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day - Infosecurity... | ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mand... | ShinyHunters targets Oracle PeopleSoft in new campaign amid FBI att... | Google Warns of ShinyHunters' Fresh Oracle PeopleSoft ... | Despite ShinyHunters arrests after FBI jobs data breach, enterprise... | ShinyHunters claims FBI breach via new Oracle PeopleSoft zero-day...