Oracle has warned corporate customers of a critical vulnerability in its PeopleSoft software that the cybercrime group ShinyHunters has been actively exploiting in a mass-hacking campaign, with more than 100 organizations potentially compromised. The advisory was published in June 2026, a day after ShinyHunters publicly claimed responsibility for the breaches.
PeopleSoft is widely used by large companies to manage payroll and human resources. According to Oracle’s advisory, the flaw can be exploited over the internet without any authentication, such as a password. No patch had been released at the time of Oracle’s warning; the company instead recommended that customers apply available mitigations. Oracle did not respond to a request for comment.
The vulnerability is classified as a zero-day, meaning Oracle had no opportunity to fix it before it was discovered and exploited. Google-owned cybersecurity firm Mandiant confirmed the flaw is the same one ShinyHunters is using in its campaign and said it has notified more than 100 global organizations — most of them in the United States — to help restrict access to vulnerable systems. Mandiant noted that roughly two-thirds of affected organizations are in higher education.
A ShinyHunters member told TechCrunch that the gang stole data from universities and colleges, including student records containing names, addresses, phone numbers, emails, dates of birth, GPAs, and enrollment details. Mandiant noted that while some organizations blocked the intrusions or patched their systems, others experienced confirmed data theft, with stolen information published on ShinyHunters’ data leak site.
The campaign follows a pattern the group has used before. Over the past year, ShinyHunters has targeted organizations sharing the same vulnerable software, including companies using Salesforce, Gainsight, and Instructure’s Canvas platform. The group typically steals data and threatens to release it unless victims pay a ransom. Earlier in 2026, education technology company Instructure confirmed it paid the hackers after being breached twice.
Source: TechCrunch