ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says

· CNA · Join
FILE PHOTO: Google logo is displayed at Google's headquarters in New York City, U.S., July 1, 2026. REUTERS/Aleksandra Michalska/File Photo
FILE PHOTO: A logo of cloud service provider Oracle is seen at the company's offices at Eastpoint Business Park, Dublin, Ireland October 18, 2021. Picture taken October 18, 2021. REUTERS/Tom Bergin//File Photo

Read a summary of this article on FAST.
Get bite-sized news via a new
cards interface. Give it a try.
Click here to return to FAST Tap here to return to FAST
FAST

Sept 25 : Google's cybersecurity unit said on Friday that hacking group ShinyHunters has renewed "mass exploitation" of a security flaw in Oracle's PeopleSoft software, after skirting defenses put up following attacks in the summer.

Mandiant made the announcement in a threat intelligence report released days after ShinyHunters, which has claimed responsibility for several major data breaches, said it had stolen FBI personnel data.

The evolving nature of the attack is likely to ring alarm bells at organizations that rely on PeopleSoft for human resources and other critical functions, and heighten concerns about the vulnerability of even well-resourced institutions.

The unit of Alphabet's Google said ShinyHunters exploited a bug in Oracle's PeopleSoft enterprise software in attacks from May 27 through June 9 that mainly affected universities.

CNA Games

Guess Word
Crack the word, one row at a time

Buzzword
Create words using the given letters

Mini Sudoku
Tiny puzzle, mighty brain teaser

Mini Crossword
Small grid, big challenge

Word Search
Spot as many words as you can
Show More
Show Less

Mandiant said the hackers adapted to defensive guidance published after the May-June attacks and targeted organizations that implemented web application firewall rules but did not apply an update that Oracle issued to patch the vulnerability.

It said, without identifying victims, that the latest attack affected dozens of systems globally in sectors as varied as higher education, technology, healthcare, agriculture, transportation and government.

ShinyHunters has said it accessed FBI data using a vulnerability in PeopleSoft. Reuters has not been able to corroborate the claim. Oracle did not respond to requests for comment.

In a statement issued Wednesday, the Federal Bureau of Investigation said it was "aggressively investigating" the reported breach.

ShinyHunters exposed the names of personnel working in sensitive FBI units and acquired medical and psychiatric records, Reuters previously reported.

Source: Reuters

Newsletter

Week in Review

Subscribe to our Chief Editor’s Week in Review

Our chief editor shares analysis and picks of the week's biggest news every Saturday.

Sign up for our newsletters

Get our pick of top stories and thought-provoking articles in your inbox

Subscribe here

Get the CNA app

Stay updated with notifications for breaking news and our best stories

Download here

Get WhatsApp alerts

Join our channel for the top reads for the day on your preferred chat app

Join here