Theme:
Light Dark Auto
GeneralPoliticsBusinessTechnologyEnvironmentSportsEntertainment
TECHNOLOGY
Negative Sentiment

ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says

PUBLISHED Sep 26, 2026, 1:09 AM ET

Read, Watch or Listen

ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says
Media Bias Meter
Sources: 30
Left 20%
Center 67%
Right 13%
Sources: 30

Alphabet's Google unit reported that the cybercriminal group ShinyHunters expanded its exploitation of a vulnerability in Oracle's PeopleSoft enterprise software between May 27 and June 9, primarily impacting universities and higher education institutions. According to Google's Mandiant threat intelligence unit, the hackers adapted their methods following defensive guidance published after earlier incidents. The attackers targeted organizations that implemented web application firewall rules but failed to install a critical software update issued by Oracle to patch the flaw. The campaign affected dozens of systems worldwide across higher education, technology, healthcare, agriculture, transportation, and government agencies. The FBI stated it is aggressively investigating the reported breaches, while Oracle and ShinyHunters have not provided immediate comments.

By Neha R. | JQJO News

Timeline of Events

  • On May 27 2026 Cybercriminal group ShinyHunters begins expanded exploitation of Oracle PeopleSoft vulnerabilities.
  • On June 9 2026 End period of the observed Mandiant threat intelligence window for the expanded attacks.
  • On September 26 2026 Google Mandiant reports on the expanded PeopleSoft vulnerability exploits affecting global organizations.
  • On September 30 2026 Ongoing federal investigations and security audits by affected institutions.

News Intelligence

  • Immediate US impact: U.S. government agencies, universities, and healthcare organizations utilizing Oracle PeopleSoft face validated exposure risks from the documented exploit campaign.
  • Possible long-term US impact: Accelerates stricter patch management enforcement and scrutiny on enterprise software supply chain security across U.S. federal and commercial sectors.
  • Most affected groups: IT security administrators, higher education institutions, U.S. federal agency personnel, and enterprise software users.
  • Reader priority: High priority for system administrators and organizations utilizing Oracle PeopleSoft software.
Media Bias
Articles Published:
30
Right Leaning:
4
Left Leaning:
6
Neutral:
20
Distribution:
Left 20%, Center 67%, Right 13%

Explain Framing

Left: leaning outlets emphasize corporate software accountability, systemic vulnerabilities in enterprise infrastructure, and the urgent need for tighter regulatory standards and proactive patching protocols across public institutions. Center: outlets focus on objective factual reporting of Google Mandiant threat intelligence data, the specific timeline of attacks (May 27 to June 9), and ongoing federal investigations by the FBI. Right: leaning outlets highlight national security risks, threats to critical government and university infrastructure, and the enforcement actions necessary to combat international cybercriminal syndicates.

Primary Source

Google Mandiant threat intelligence report detailing ShinyHunters cyberattack expansion on Oracle PeopleSoft. https://www.investing.com/news/stock-market-news/shinyhunters-hackers-expanded-attacks-on-oracles-peoplesoft-google-says-4918395

Coverage of Story:

Comments

Login
JQJO App
Get JQJO App
Read news faster on our app
GET