ShinyHunters expands attacks on Oracle's PeopleSoft, Google reports
by@Reuters
Summary
On September 25, Google's cybersecurity unit reported that the hacking group ShinyHunters has resumed extensive exploitation of a security flaw in Oracle's PeopleSoft software, which had previously been targeted in attacks over the summer. Despite defenses implemented after those earlier incidents, ShinyHunters adapted its techniques to target organizations that failed to apply an Oracle-issued patch, affecting systems across various sectors, including education and government. The group has also claimed responsibility for accessing FBI personnel data, raising alarms about the vulnerabilities within widely used enterprise applications like PeopleSoft, especially when timely updates are not applied.
Tokens
$ORCL$GOOGL
Analysis
Google: Google, through its cybersecurity divisions including Mandiant and the Threat Intelligence Group, monitors and reports on active cyber threats worldwide. Its recent threat intelligence publication detailed the expansion of ShinyHunters' PeopleSoft attacks across multiple sectors globally. The company is part of Alphabet and focuses on protecting users and organizations from evolving digital risks. Oracle: Oracle is a major provider of enterprise software solutions, including the PeopleSoft suite used for human resources, finance, and other critical business functions. In this incident, attackers have repeatedly targeted a vulnerability in PeopleSoft, highlighting ongoing risks to organizations relying on the platform. Oracle issued a patch following earlier attacks but many systems remain unupdated. Mandiant: Mandiant is a leading cybersecurity firm specializing in threat intelligence, incident response, and vulnerability research, now operating as part of Google. It authored the September 2026 report identifying ShinyHunters' renewed exploitation campaign against Oracle PeopleSoft after earlier defensive guidance was issued. The firm has tracked the group's adaptation to web application firewall rules without full patching. ShinyHunters: ShinyHunters is a financially motivated hacking group known for large-scale data theft and extortion operations targeting various industries. The group has adapted its tactics in the current campaign to circumvent defensive measures on Oracle PeopleSoft systems and claims involvement in breaching sensitive FBI data. Mandiant attributes the renewed mass exploitation activity directly to this actor. Federal Bureau of Investigation: The Federal Bureau of Investigation is the primary federal law enforcement agency in the United States responsible for investigating cybercrimes and national security threats. It has confirmed an active investigation into ShinyHunters' claimed access to FBI personnel data via the PeopleSoft vulnerability. The agency emphasized its aggressive response to the reported breach involving sensitive records. Threat Adaptation: Attackers are modifying exploit techniques to bypass web application firewall rules deployed after initial disclosures, allowing continued access to vulnerable systems. Law Enforcement Action: Federal agencies are prioritizing investigations into claims of breaches involving sensitive government personnel data to mitigate potential national security implications. Enterprise Software Exposure: Widely deployed enterprise applications like PeopleSoft remain attractive targets when patches are not applied promptly, even in well-resourced organizations across education, healthcare, and government sectors.
Categories
tech
Related sources
- https://techcrunch.com/2026/06/11/oracle-warns-of-security-bug-that-hackers-abused-to-breach-100-companies/
- https://www.fortiguard.com/threat-signal-report/6468/oracle-peoplesoft-zero-day
- https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
- https://urlscan.io/result/019eca31-8cc6-71ca-8718-f92c8e9b551c/content/
- https://tech-insider.org/shinyhunters-oracle-peoplesoft-breach-2026/
- https://www.decryptiondigest.com/blog/shinyhunters-apt-profile-oracle-peoplesoft-2026
- https://blog.elvis.hk/mandiant/threat-intelligence
- https://www.fortiguard.com/threat-actor/6380
- https://www.reuters.com/legal/government/shinyhunters-hackers-expanded-attacks-oracles-peoplesoft-google-says-2026-09-26/
- https://www.youtube.com/watch?v=yxpEHGOJAw4
- https://arstechnica.com/security/2026/06/peoplesoft-0-day-affecting-hundreds-of-organizations-steals-gigabytes-of-data/
- https://www.esentry.io/articles/threat-actor-profile-shinyhunters-shinycorp