INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Hack Oracle PeopleSoft Servers in Data Theft Attacks
| 2026-06-10 18:31 DATA BREACH
Executive Summary
AI-generated
Oracle PeopleSoft servers were targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 300 instances across more than 100 organizations. The attack is believed to be conducted using a "gadget chain" of old and zero-day vulnerabilities, but its success may depend on how an instance is configured. Most of the affected organizations are in the education sector, with many previously extorted by the threat actor. The attacks were not successful against Nottingham University's FBI portal running PeopleSoft, which was initially targeted as part of the group's goal to "publish a statement and set the record straight."
Technical Mitigations AI-generated
• Data Backup (ATT&CK mitigation for Defacement): Consider implementing IT disaster recovery plans that contain procedures for taking regular data backups that can be used to restore organizational data. Ensure backups a
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
in•••••.these
RE•••••.TXT
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
Tactical Metrics
Intelligence Sources
BleepingComputer
2026-06-10
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
BleepingComputer