ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

ShinyHunters exploited Oracle PeopleSoft flaw to victimise hundreds of organisations

The ShinyHunters extortion group has claimed that it stole vast amounts of data from over a hundred organisations by breaching Oracle’s PeopleSoft HR application.

 

The news came to light after BleepingComputer tracked a large number of data theft attacks that involved hackers hijacking Oracle PeopleSoft cloud and on-premise instances at multiple organisations. 

 

Oracle PeopleSoft is an enterprise resource planning and human capital management software suite, enabling universities, healthcare organisations and public sector entities, among others, to manage workforce, supply chains and financial operations.  

 

Organisations impacted by the hacking attacks on their PeopleSoft instances told BleepingComputer that they received extortion demands from threat actors claiming to represent the ShunyHunters extortion group.

 

When contacted, the hacker group admitted to carrying out the attacks, claiming that it stole data from up to 300 PeopleSoft instances across more than a hundred organisations.

 

Oracle PeopleSoft is used by about 9,500 organisations worldwide, especially large-scale enterprises that require heavy on-premise or hybrid cloud customisation to manage complex and round-the-clock billing, logistics, payroll, procurement, lifecycle management and administrative operations.

 

In the US, Oracle PeopleSoft customers include Amazon, Walmart, Microsoft, Apple, Samsung, Google, CVS Health, IBM and McKesson. It is unclear if any of these global organisations were impacted by the hacking attacks.

 

The hacker group said it exploited a range of old and zero-day vulnerabilities to target the enterprise resource planning platform, but could not victimise every organisation that used the software. The success of each attack depended on how each PeopleSoft instance was configured. Organisations that ShinyHunters claims to have victimised include Nottingham University.

 

Soon after ShinyHunters claimed the attacks, Oracle said its PeopleSoft application featured a zero-day vulnerability, tracked as CVE-2026-35273, that enabled threat actors to carry out remote code exploitation without authentication.

 

"This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution," Oracle said. The company did not address the targeting of over a hundred customer organisations by the ShinyHunters group, and did not state if the vulnerability was associated with the attacks.

 

"We consider implementation of the recommended mitigations to be a high-priority risk reduction measure and strongly recommend immediate action to address the identified exposure. Oracle always recommends that customers remain on actively-supported versions and apply all Critical Patch Updates, Critical Security Patch Updates and Security Alerts without delay," the company added.

 

Oracle has released emergency mitigations to help customer organisations address the zero-day vulnerability, and will release a patch in due course to eliminate the flaw.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543