ShinyHunters has claimed a broad intrusion campaign against Oracle PeopleSoft servers, saying it compromised roughly 300 instances across more than 100 organizations, with universities and other education-sector entities appearing to be the primary victims. The group told reporters it exfiltrated sensitive student and administrative records, including applicant, financial aid, immigration, health, and contact data, and identified Nottingham University as one victim; the university acknowledged a cybersecurity incident. One member of the group also said an attempted breach of an FBI PeopleSoft server was intended to post a denial of the gang’s involvement in recent swatting incidents, but that effort allegedly failed.
Reporting indicates the attacks are tied to data theft and extortion activity and may involve a gadget chain using older flaws alongside a possible zero-day, with impact varying by PeopleSoft configuration. Independent research found exposed directories containing tooling linked to the campaign, including MeshCentral agents, a defacement script, a credential-spraying tool, and infrastructure associated through TLS certificates with azurenetfiles[.]net. Investigators also observed a shell script that parsed /etc/hosts, attempted SSH access with common PeopleSoft and Oracle administrative accounts, and dropped a ransom note named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT on compromised internal PeopleSoft servers, while Oracle had not publicly commented on the allegations at the time of reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Nissan Americas disclosed that a cyberattack involving Oracle PeopleSoft may have exposed sensitive employee data, including payroll records, bank details, Social Security numbers, tax records, and dependent information. Nissan said Oracle notified it of a cyber event affecting personnel records at hundreds of companies and that it later learned it had been specifically targeted, prompting incident response, outside forensic support, and coordination with law enforcement.
The National Association of Insurance Commissioners confirmed it suffered a cyberattack linked to ShinyHunters after detecting the breach on June 11 and publicly disclosing it on June 17. NAIC said exposed data included statutory financial reports, insurer investment credit rating data, and technical materials, while the threat actor claimed to have stolen 3.1 TB and later leaked it online.
ShinyHunters claimed it breached the Council of Europe via the PeopleSoft campaign and stole 297 GB of data comprising 429,000 files, including HR, payroll, banking, tax, and medical records. The Council of Europe confirmed it is investigating the matter.
Mandiant and Rapid7 published indicators of compromise related to the PeopleSoft exploitation campaign and urged customers to take immediate defensive action. The reporting also described attacker reconnaissance of PeopleSoft and WebLogic configuration files and SSH-based exfiltration to infrastructure hosting the ShinyHunters leak site.
Mandiant warned that exploitation of CVE-2026-35273 and related extortion activity were still ongoing, indicating the PeopleSoft campaign had not ended after Oracle's alert and victim notifications. The report said ShinyHunters was actively extorting universities while no patch had yet been released.
Google Mandiant attributed the PeopleSoft exploitation activity to UNC6240 and said it observed attacks exploiting CVE-2026-35273 from 2026-05-27 through 2026-06-09, before Oracle published its advisory. Mandiant also said it notified more than 100 organizations with vulnerable endpoints, with 68% in higher education.
After the PeopleSoft incident became public, Oracle issued an out-of-band security alert for CVE-2026-35273, a critical PeopleSoft Enterprise PeopleTools flaw said to allow remote unauthenticated compromise. The reference says Oracle had reportedly released mitigations, though it was unclear whether a full patch was available.
The University of Nottingham disclosed that attackers accessed its student records system, exposing data affecting 454,600 current and former students. The university said it reported the incident to the UK's Information Commissioner's Office and Action Fraud and is working with the third-party platform maintainer on a forensic investigation.
After being identified by the threat actor as a victim, Nottingham University acknowledged that it had experienced a cybersecurity incident. The reference does not provide a specific date for the university's acknowledgment.
Independent researcher Michael R found exposed directories containing tooling linked to the attacks, including MeshCentral agents, a defacement script, a credential spray script, and infrastructure associated via TLS certificates with azurenetfiles[.]net. The tooling also included a shell script that parsed /etc/hosts, attempted SSH access with common PeopleSoft and Oracle administrative accounts, and dropped a ransom note on compromised internal PeopleSoft servers.
ShinyHunters claimed it compromised Oracle PeopleSoft servers at more than 100 organizations and exfiltrated data from roughly 300 instances, with many alleged victims in the education sector. The group said it used a gadget chain involving old and zero-day vulnerabilities, with success depending partly on instance configuration.
Archives of data stolen in the PeopleSoft campaign were published on June 9, 2026, on infrastructure linked to the ShinyHunters data leak site. The reference says the exfiltrated data had been compressed with zstd and transferred to that infrastructure before publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
31 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecysecurity.news
Open sourceitpro.com
Open sourcesecurityweek.com
Open sourcetheregister.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.