Skip to main content
Mallory
Back to intelligence
education-sector-threatunderground-data-leakcredential-access-methodinternet-facing-service-vulnerability

ShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Theft Campaign

Updated 17h agoFirst seen Jun 10, 202613 sources

ShinyHunters has claimed a broad intrusion campaign against Oracle PeopleSoft servers, saying it compromised roughly 300 instances across more than 100 organizations, with universities and other education-sector entities appearing to be the primary victims. The group told reporters it exfiltrated sensitive student and administrative records, including applicant, financial aid, immigration, health, and contact data, and identified Nottingham University as one victim; the university acknowledged a cybersecurity incident. One member of the group also said an attempted breach of an FBI PeopleSoft server was intended to post a denial of the gang’s involvement in recent swatting incidents, but that effort allegedly failed.

Reporting indicates the attacks are tied to data theft and extortion activity and may involve a gadget chain using older flaws alongside a possible zero-day, with impact varying by PeopleSoft configuration. Independent research found exposed directories containing tooling linked to the campaign, including MeshCentral agents, a defacement script, a credential-spraying tool, and infrastructure associated through TLS certificates with azurenetfiles[.]net. Investigators also observed a shell script that parsed /etc/hosts, attempted SSH access with common PeopleSoft and Oracle administrative accounts, and dropped a ransom note named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT on compromised internal PeopleSoft servers, while Oracle had not publicly commented on the allegations at the time of reporting.

Share:
ShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Theft Campaign
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jun 12, 20262d ago

Mandiant and Rapid7 publish PeopleSoft IOCs and defensive guidance

Mandiant and Rapid7 published indicators of compromise related to the PeopleSoft exploitation campaign and urged customers to take immediate defensive action. The reporting also described attacker reconnaissance of PeopleSoft and WebLogic configuration files and SSH-based exfiltration to infrastructure hosting the ShinyHunters leak site.

PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data - Ars Technica

Mandiant says PeopleSoft extortion campaign remains active

Mandiant warned that exploitation of CVE-2026-35273 and related extortion activity were still ongoing, indicating the PeopleSoft campaign had not ended after Oracle's alert and victim notifications. The report said ShinyHunters was actively extorting universities while no patch had yet been released.

ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw | CyberScoop
Jun 11, 20263d ago

Mandiant attributes PeopleSoft attacks to UNC6240

Google Mandiant attributed the PeopleSoft exploitation activity to UNC6240 and said it observed attacks exploiting CVE-2026-35273 from 2026-05-27 through 2026-06-09, before Oracle published its advisory. Mandiant also said it notified more than 100 organizations with vulnerable endpoints, with 68% in higher education.

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

Oracle issues security alert and mitigations for CVE-2026-35273

After the PeopleSoft incident became public, Oracle issued an out-of-band security alert for CVE-2026-35273, a critical PeopleSoft Enterprise PeopleTools flaw said to allow remote unauthenticated compromise. The reference says Oracle had reportedly released mitigations, though it was unclear whether a full patch was available.

ShinyHunters claims Oracle PeopleSoft 0-day hit 100+ orgs

Nottingham breach disclosed as affecting 454,600 people

The University of Nottingham disclosed that attackers accessed its student records system, exposing data affecting 454,600 current and former students. The university said it reported the incident to the UK's Information Commissioner's Office and Action Fraud and is working with the third-party platform maintainer on a forensic investigation.

Nottingham University data breach affects over 450,000 students
Jun 10, 20264d ago

Nottingham University acknowledges a cybersecurity incident

After being identified by the threat actor as a victim, Nottingham University acknowledged that it had experienced a cybersecurity incident. The reference does not provide a specific date for the university's acknowledgment.

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

Researcher uncovers tooling and infrastructure tied to the campaign

Independent researcher Michael R found exposed directories containing tooling linked to the attacks, including MeshCentral agents, a defacement script, a credential spray script, and infrastructure associated via TLS certificates with azurenetfiles[.]net. The tooling also included a shell script that parsed /etc/hosts, attempted SSH access with common PeopleSoft and Oracle administrative accounts, and dropped a ransom note on compromised internal PeopleSoft servers.

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

ShinyHunters launches PeopleSoft data theft campaign

ShinyHunters claimed it compromised Oracle PeopleSoft servers at more than 100 organizations and exfiltrated data from roughly 300 instances, with many alleged victims in the education sector. The group said it used a gadget chain involving old and zero-day vulnerabilities, with success depending partly on instance configuration.

Cybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizations | TechCrunch
Jun 9, 20265d ago

Stolen PeopleSoft data published on ShinyHunters leak infrastructure

Archives of data stolen in the PeopleSoft campaign were published on June 9, 2026, on infrastructure linked to the ShinyHunters data leak site. The reference says the exfiltrated data had been compressed with zstd and transferred to that infrastructure before publication.

Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters - Cyber Security News
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

35 LINKEDOpen in app
Threat actors
2 linked
Affected products
7 linked
Oracle Weblogic ServerSalesforceMeshcentralPeoplesoft Enterprise PeopletoolsOracle Peoplesoft PeopletoolsPeoplesoftOracle E-Business Suite
Organizations
19 linked
OracleGoogleSalesforceUniversity of NottinghamRapid7Banco SantanderSnowflakeTicketmasterBleepingComputerInstructureMicrosoft CorporationTrend MicroHave I Been PwnedTechCrunchCisco SystemsThe RegisterUniversity of OxfordGainsightCyberScoop
Breaches
6 linked
UNIVERSITYOFNOTTINGHAM-2026-06TICKETMASTER-2026-06SNOWFLAKE-2026-06INSTRUCTURE-2026-06NOTTINGHAMUNIVERSITY-2026-06MORETHAN100ORGANIZATIONSUSINGORACLEPEOPLESOFT-2026-06
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

ShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Theft Campaign | Mallory