Quick Facts

  • ShinyHunters claims to have breached 300 Oracle PeopleSoft instances across more than 100 organizations
  • Most victims are universities, with Nottingham University already confirmed as compromised
  • The group used a combination of old and zero-day vulnerabilities to conduct the attacks

The notorious cybercrime group ShinyHunters claimed responsibility for hacking Oracle PeopleSoft servers at more than 100 organizations. The group confirmed to TechCrunch that they stole data from 300 instances, with most victims in the education sector.

Nottingham University stands as the first confirmed victim. The university’s data appeared on ShinyHunters’ leak site, and the institution publicly acknowledged the incident. The compromised data includes student, applicant, financial aid, immigration, health, and administrative records according to messages sent to victims.

Attack Methods and Technical Details

ShinyHunters exploited what they describe as a “gadget chain” of old and zero-day vulnerabilities. The attacks do not work on all systems, with success appearing to depend on instance configuration.

Cybersecurity researcher Michael R discovered exposed online directories containing attack tools. These included MeshCentral agents, credential spray scripts, and IP addresses using TLS certificates linked to ShinyHunters.

The attack scripts parse /etc/hosts files to identify PeopleSoft systems and attempt SSH connections using common administrative accounts like “psoft,” “oracle,” and “linuxadm.” When password authentication fails, the scripts attempt SSH key-based authentication.

Group’s Broader Campaign

ShinyHunters has claimed responsibility for stealing over 1.5 billion records from more than 1,000 organizations between 2025 and 2026. The group’s original goal was compromising an FBI PeopleSoft server to post a statement denying involvement in recent swatting attempts.

The Wynn Resorts breach in September 2025 demonstrates the financial stakes involved. ShinyHunters demanded 22.34 BTC, equivalent to approximately $1.5 million at the time, after exposing personal information of over 800,000 employees.

Oracle’s Response and Security Implications

Oracle has not responded to multiple requests for comment about the breaches or the alleged zero-day vulnerabilities. The company has not publicly acknowledged the incidents.

Security experts recommend organizations using PeopleSoft check log files for suspicious connections and verify systems for unauthorized access. If indicators of compromise are found, organizations should begin immediate incident response and consider removing affected servers from internet access.

The compromise of PeopleSoft systems poses significant risks since these platforms handle HR, payroll, and financial operations. Supply chain risks extend beyond direct users to third-party processors using PeopleSoft for client services.

Read more: Cybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizations

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.