ShinyHunters reportedly exploited a critical zero-day vulnerability in Oracle PeopleSoft during May and early June 2026, compromising about 300 PeopleSoft instances at roughly 100 organizations worldwide. The Council of Europe was among the alleged victims; attackers targeted ERP management and configuration layers to steal employee and student personal data, payroll, tax, financial, health, immigration, and passport records. The Council reportedly declined to negotiate or pay.
Reported extortion demands ranged from $400,000 to $2.3 million per victim. The incident highlights the exposure created by cloud and SaaS supply-chain dependencies and the need for rapid risk-based remediation, Zero Trust and identity controls, dependency mapping, isolated immutable backups, and regularly tested cyber-recovery plans.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
In May and early June 2026, ShinyHunters reportedly exploited a critical Oracle PeopleSoft zero-day, targeting ERP management and configuration layers to steal data and extort victims. The campaign reportedly affected about 100 organizations and approximately 300 PeopleSoft instances worldwide, including the Council of Europe; stolen records included personal, payroll, tax, financial, health, immigration, and passport data.
The Council of Europe, among the organizations reportedly affected by the PeopleSoft campaign, refused to negotiate with or pay the extortionists. Reported demands ranged from $400,000 to $2.3 million per victim and were often requested in Bitcoin.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.