IGMPI facebook ShinyHunters Resumes Large-Scale Exploitation of Oracle PeopleSoft Vulnerability
IGMPI Logo
Centre for Cyber Forensic and Cyber Security

(An Autonomous Body Recognized by Ministry of Commerce & Industry, Government of India)

Competency based placement focussed Education | Training | Research | Consultancy

18001031071 (Toll Free), +91 11 26512850

C-6, Qutab Institutional Area, Near Old JNU Campus, New Delhi-110016

Regular | Part-time (Online Live Classes) Modes
ShinyHunters Resumes Large-Scale Exploitation of Oracle PeopleSoft Vulnerability

ShinyHunters Resumes Large-Scale Exploitation of Oracle PeopleSoft Vulnerability

Cybersecurity researchers have warned that the hacking group ShinyHunters has resumed widespread attacks against organisations using Oracle's PeopleSoft enterprise software. Google's cybersecurity division, Mandiant, reported that the group has adapted its techniques and is again exploiting a vulnerability that had already been used in attacks earlier this year.

PeopleSoft is widely used by organisations to manage important business functions, including human resources, payroll and other administrative operations. The renewed campaign has reportedly affected systems belonging to organisations in several sectors, including higher education, healthcare, government, technology, agriculture and transportation.

According to Mandiant, ShinyHunters initially exploited the PeopleSoft vulnerability between 27 May and 9 June 2026, with universities among the organisations affected. Following those attacks, security guidance and defensive measures were introduced, including web application firewall rules and an Oracle software update intended to address the vulnerability.

The latest activity indicates that some organisations implemented additional network protections but had not installed the available security update. Mandiant reported that attackers modified their approach to bypass certain defensive measures and continue exploiting vulnerable systems.

The campaign has attracted additional attention after ShinyHunters claimed that it had obtained sensitive information belonging to the Federal Bureau of Investigation (FBI) through a PeopleSoft vulnerability. The claim has not been independently verified. The FBI has confirmed that it is investigating the reported incident.

The renewed attacks demonstrate how a publicly disclosed software vulnerability can continue to pose a threat when affected systems remain unpatched. They also show how threat actors can alter their methods in response to security measures introduced after an initial wave of attacks.

Organisations using PeopleSoft have therefore been urged to review their systems, apply available security updates and examine their existing protective controls in light of the renewed exploitation campaign.

26-09-2026