:

SHINY HUNTERS BREACH ORACLE PEOPLESOFT AT 100+ ORGS

SECURITY DESK2 MIN READ
WED, JUN 10, 2026

■ AI-SUMMARIZED FROM 5 SOURCES ▸ TIMELINE

The ShinyHunters extortion gang claims to have compromised Oracle PeopleSoft servers across more than 100 organizations, including numerous universities, in an ongoing data theft campaign.

ShinyHunters, a known cybercriminal group, has targeted Oracle PeopleSoft infrastructure in attacks affecting over 100 entities. The gang operates an extortion scheme, typically demanding payment in exchange for not publishing stolen data. Oracle PeopleSoft is a widely deployed human capital management and enterprise resource planning system used by organizations across sectors including higher education, government, and private industry. The breadth of the breach underscores the risk posed by vulnerabilities in popular enterprise software platforms. The ShinyHunters group has become increasingly active in recent years, carrying out high-profile attacks against major organizations and publishing data when extortion demands go unmet. Their claims of accessing PeopleSoft systems across universities and other institutions represent a significant security incident, though the specific vulnerabilities exploited remain unclear. Oracle has not yet issued a public statement regarding the breach. The company typically addresses security issues through its quarterly patch releases and security advisories. Organizations running PeopleSoft should review their systems for signs of compromise and consult Oracle's security guidance. The timing of the disclosure coincides with Oracle's recent earnings report, which saw shares decline following higher-than-expected capital expenditure figures related to AI infrastructure investments. Investors expressed concerns about the profitability of Oracle's AI business expansion, adding pressure to the company amid broader market uncertainty. Securityresearchers recommend affected organizations conduct forensic investigations, reset credentials, and review access logs for unauthorized activity. Those targeted by ShinyHunters should also prepare for potential extortion demands and consider reporting the breach to relevant law enforcement agencies and regulators.

■ MORE FROM THE SECURITY DESK

A cross-site request forgery (CSRF) vulnerability in WordPress Core, dubbed 'Click2Shell,' enables attackers to execute PHP code on vulnerable servers. Technical details and working exploits are now public.

7H AGOSecurity Desk

The ShinyHunters extortion group took control of the dark web leak site belonging to the prolific Cl0p ransomware gang over the weekend. The attackers set an eight-figure extortion demand pegged at 2.333% of Cl0p's estimated net worth.

8H AGOSecurity Desk

The FBI's CJIS Security Policy v6.1 strengthens encryption requirements and vulnerability scanning mandates. Agencies must prepare for updated password, MFA, and identity verification standards ahead of compliance audits.

10H AGOSecurity Desk

New research reveals that digital watermarks intended to protect content ownership are being repurposed as surveillance mechanisms to track user behavior and identify individuals across platforms.

10H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.