ShinyHunters hackers expanded attacks on Oracle’s PeopleSoft, Google says
thestar.com.my Sep 26, 2026

ShinyHunters hackers expanded attacks on Oracle’s PeopleSoft, Google says

AI-summarised brief · reviewed before publication

Google’s Mandiant unit reported that the ShinyHunters hacking group has resumed large‑scale exploitation of a vulnerability in Oracle’s PeopleSoft enterprise software. The group first abused the flaw from May 27 to June 9, mainly hitting universities, and then altered its tactics after Oracle released a patch and vendors issued web‑application‑firewall guidance. In the new wave, attackers bypassed those defenses by targeting organizations that applied firewall rules but failed to install the Oracle update. The campaign has reached dozens of systems worldwide across higher education, technology, healthcare, agriculture, transportation and government sectors. ShinyHunters also claimed to have accessed FBI personnel records, including medical and psychiatric data, prompting an FBI investigation. Oracle declined comment. It reveals how quickly attackers can pivot around simple patches.

💡 Why It Matters

  • · Enterprises using PeopleSoft now face immediate pressure to verify patch compliance, as the attack proves that even basic updates can be bypassed.