Cybersecurity

A 9.8/10 Oracle PeopleSoft flaw gave ShinyHunters two weeks in 100+ organizations

Susan Hill

More than 100 organizations running Oracle PeopleSoft discovered they had been inside ShinyHunters’ extortion network before they received notification. The vulnerability that enabled the campaign — CVE-2026-35273, rated 9.8 out of 10 in severity — requires no authentication, no user interaction, and nothing more than network access over HTTP to deliver full remote code execution on an exposed server.

The flaw sits in PeopleSoft’s PeopleTools Updates Environment Management component, a module common to the HR, student information, and financial management deployments that universities and corporations depend on. Attackers chain it with older known weaknesses in what security researchers call a gadget chain, extracting credentials from configuration files and then mapping connected application, web, and batch tiers across each victim’s infrastructure. ShinyHunters worked through more than 300 server instances across the organizations they hit.

ShinyHunters operates on a data-theft-and-extortion model rather than encryption. They exfiltrate records, list the data on an extortion portal, and release staged leaks to pressure victims into payment. Compromised systems were left with a file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT. Mandiant identified the scope of the campaign and notified affected organizations; Arctic Wolf published detailed forensic analysis of the group’s tooling and lateral movement patterns.

Higher-education institutions took 68 percent of the impact — a predictable consequence of universities running PeopleSoft as the backbone of both HR and student information systems in the same deployment. The University of Nottingham confirmed a breach in which ShinyHunters published more than 40 gigabytes of data covering nearly 500,000 current and former students. The National Association of Insurance Commissioners reported 3.1 terabytes stolen. Named corporate victims include Nissan, which saw employee records from the United States, Canada, Mexico, and Brazil exposed, plus Kubota North America and an Aflac Japan subsidiary.

Data extracted across the campaign spans the most sensitive categories PeopleSoft manages: names, contact details, bank account information, tax records, government-issued identification numbers, and records covering dependents and beneficiaries. For universities, that extends to financial aid records and student IDs. The combination makes PeopleSoft a high-yield target — a single compromised installation typically holds the complete financial profile of an entire institution’s workforce and student population.

The exploitation window ran from May 27 through June 9. Oracle issued an out-of-band emergency advisory on June 10, closing the active attack vector. The permanent fix arrived on July 21 as part of Oracle’s quarterly Critical Patch Update — one of the largest in the company’s history, addressing 1,455 newly disclosed vulnerabilities including ten rated CVSS 10.0. Organizations that applied only the June emergency advisory should verify the July CPU is in place; the out-of-band patch closed the ShinyHunters-exploited vector but did not remediate the full vulnerability chain.

Oracle recommends immediately applying the July CPU, temporarily restricting network access to PeopleSoft instances, and implementing WAF rules that disable the Updates Environment Management component at the network edge. For individuals connected to affected organizations — anyone whose university, insurer, or employer runs PeopleSoft for HR, payroll, or student administration — ShinyHunters’ staged-release model means data that has not yet appeared publicly could still surface on leak portals in coming weeks. Checking credit reports and monitoring for suspicious government-ID use is the practical near-term step.

Tags: , , , , ,

Discussion

There are 0 comments.