ShinyHunters Exploit Oracle PeopleSoft 0-day: More than 100 Compromised

ShinyHunters Mischief in Oracle PeopleSoft

The data theft and extortion group ShinyHunters has taken advantage of a significant bug in Oracle PeopleSoft, identified as a zero-day, to breach over 100 organizations, including the University of Nottingham, across 300 susceptible instances. A representative from the cybercriminal organization revealed to GadgetLad on Thursday that they utilized CVE-2026-35273 to infiltrate the university’s PeopleSoft system and steal 40 GB of personal data and billing information belonging to hundreds of thousands of current and former students.

University’s Data Held Hostage

On Tuesday, ShinyHunters listed the UK university on its data leak site before releasing the stolen documents later the same day, likely because the institution declined to pay the ransom. “The University of Nottingham on our leak site is one of the initial publicly acknowledged incidents,” a ShinyHunters representative stated. “We have merely initiated outreach to affected organizations and are actively seeking to establish an agreement with impacted entities.” They did not disclose when they plan to reveal the other approximately 100 claimed victims.

Google Confirms the Chaos

A Google threat intelligence report released Thursday afternoon supported ShinyHunters’ assertions regarding compromising over 100 organizations. Google reported observing suspicious activity, “consistent with the exploitation of CVE-2026-35273,” between May 27 and June 9, and alerted more than 100 global organizations “whose IP addresses matched potentially vulnerable endpoints.” Most of these, as noted, are situated in the US, with a significant 68 percent residing in the higher-education sector.

PeopleSoft: A Juicy Target

PeopleSoft is a popular suite of enterprise software that major companies and institutions utilize to oversee human resources, payroll, billing applications, supply chains, and student records. CVE-2026-35273 carries a CVSS rating of 9.8, making it an attractive target, allowing remote, unauthenticated attackers with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools and completely seize control of the platform.

No Word From Oracle

On Wednesday, a day after ShinyHunters exposed the institution’s data, the University of Nottingham confirmed the breach, and Oracle issued an out-of-band security advisory. However, it remains unclear if the software provider has rolled out a patch to address the security vulnerability. GadgetLad contacted Oracle, and unsurprisingly, did not receive any answers to our queries. Charles Carmakal, a chief tech expert at Google-owned Mandiant, cautioned in a brief LinkedIn post on Thursday that PeopleSoft was one of two zero-day vulnerabilities “actively being exploited in the wild.” “Oracle released mitigations,” Carmakal stated. “Patches should be forthcoming.”

Cisco Catalyst Chaos

The other zero-day, for the record, is this Cisco Catalyst SD-WAN Manager vulnerability.

Summary

Oops, They Did It Again: ShinyHunters are back at it, creating trouble and making off with valuable data, while the rest of us are left to deal with the aftermath. Time for Oracle to step up their game, right?