logo

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

ID: 51d9cb28-6f59-5224-b2cd-57225a7a1a5c

STIX ID: report--51d9cb28-6f59-5224-b2cd-57225a7a1a5c

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Lawrence Abrams

...
...

ShinyHunters is actively targeting Oracle PeopleSoft instances (cloud and on‑prem) in a large-scale data-theft and extortion campaign, claiming data from ~300 instances across 100+ organizations (primarily education). The actor reportedly uses a mix of old and zero‑day vulnerabilities plus SSH credential/key access, exposed tooling and scripts to drop ransom notes; several IP addresses and artifacts were published as IOCs and organizations using PeopleSoft are advised to investigate and isolate affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.