ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says
PUBLISHED Sep 26, 2026, 1:09 AM ET
Read, Watch or Listen
Alphabet's Google unit reported that the cybercriminal group ShinyHunters expanded its exploitation of a vulnerability in Oracle's PeopleSoft enterprise software between May 27 and June 9, primarily impacting universities and higher education institutions. According to Google's Mandiant threat intelligence unit, the hackers adapted their methods following defensive guidance published after earlier incidents. The attackers targeted organizations that implemented web application firewall rules but failed to install a critical software update issued by Oracle to patch the flaw. The campaign affected dozens of systems worldwide across higher education, technology, healthcare, agriculture, transportation, and government agencies. The FBI stated it is aggressively investigating the reported breaches, while Oracle and ShinyHunters have not provided immediate comments.
By Neha R. | JQJO News
Timeline of Events
- On May 27 2026 Cybercriminal group ShinyHunters begins expanded exploitation of Oracle PeopleSoft vulnerabilities.
- On June 9 2026 End period of the observed Mandiant threat intelligence window for the expanded attacks.
- On September 26 2026 Google Mandiant reports on the expanded PeopleSoft vulnerability exploits affecting global organizations.
- On September 30 2026 Ongoing federal investigations and security audits by affected institutions.
News Intelligence
- Immediate US impact: U.S. government agencies, universities, and healthcare organizations utilizing Oracle PeopleSoft face validated exposure risks from the documented exploit campaign.
- Possible long-term US impact: Accelerates stricter patch management enforcement and scrutiny on enterprise software supply chain security across U.S. federal and commercial sectors.
- Most affected groups: IT security administrators, higher education institutions, U.S. federal agency personnel, and enterprise software users.
- Reader priority: High priority for system administrators and organizations utilizing Oracle PeopleSoft software.
Coverage of Story:
From Left
Hackers expand Oracle PeopleSoft attacks as uncovered by Google threat intel
The Verge Ars Technica Wired Washington Post New York Times CNNFrom Center
ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says
Reuters Investing.com Bloomberg Associated Press CNBC Financial Times TechCrunch Forbes Bleeping Computer The Record by Recorded Future Dark Reading SecurityWeek CyberScoop InfoSecurity Magazine SC Media The Register US News & World Report Chicago Tribune Boston Globe Reuters (Syndicated)From Right
Oracle PeopleSoft Software Targeted in Expanded Hacker Campaign, Google Says
Wall Street Journal Fox News National Review New York Post
Comments