SHINYUNTERS GROUP CLAIMS ATTACK ON ORACLE PEOPLESOFT SERVERS
ShinyHunters, an extortion group, has claimed responsibility for compromising more than 100 organisations through exploitation of a vulnerability in Oracle PeopleSoft servers. The attackers claim to have exfiltrated data from approximately 300 PeopleSoft instances using a flaw tracked as CVE-2026-35273. Victims have received extortion demands threatening data release unless ransom is paid. The vulnerability affects PeopleSoft versions 8.61 and 8.62 and allows remote code execution without authentication.
Google's Mandiant division tracked the exploitation of the vulnerability as a zero-day between 27 May and 9 June 2026, prior to Oracle's public advisory on 10 June. Mandiant alerted over 100 global organisations whose IP addresses correlated with potentially vulnerable endpoints. Two-thirds of identified victims were higher education institutions, with the majority based in the United States. The vulnerability carries a CVSS severity rating of 9.8.
Oracle has urged users to apply security patches immediately to fix the affected versions. Mandiant recommends that organisations check system logs for suspicious access between late May and early June and apply Oracle's security update regardless of whether they have experienced an attack. PeopleSoft servers are widely used by universities, businesses and public sector organisations across multiple sectors.