ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
The Google-owned security firm Mandiant published a blog on Friday about CVE-2026-35273 — a vulnerability disclosed in June that impacts Oracle’s PeopleSoft. PeopleSoft is used widely across government, education and healthcare for a variety of business tasks like managing invoices, projects and staffing.
Mandiant reported in June that ShinyHunters was exploiting the bug as a zero-day between May 27 and June 9 in attacks on academic institutions. Oracle eventually released a patch on June 10 and Mandiant provided guidance on how organizations could either install the patch or institute workarounds.
In its blog on Friday, Mandiant warned that ShinyHunters had restarted its exploitation of the bug and “adapted to published defensive guidance, targeting organizations that implemented [workarounds] but did not patch the vulnerability.”
“Our analysis indicates that the threat actor expanded their targeting in this recent campaign, deploying web shells on dozens of systems globally, spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government,” Mandiant said.
Last week, ShinyHunters took credit for an attack on the FBI that saw the group deface a jobs website run by the agency and allegedly steal troves of sensitive data on FBI operations and agents.
In a memo to FBI employees obtained by the New York Times, senior officials at the agency acknowledged the breach and said they are “operating under the premise that the threat actor is also exfiltrating [personal information] of all F.B.I. employees.”
On its website and in interviews with news outlets, ShinyHunters claimed it breached the FBI through a vulnerability in Oracle PeopleSoft — setting off a scramble to determine if the group found a new bug in the software or if it was exploiting a past issue.
Mandiant said it analyzed multiple compromised instances where the hackers were able to exploit the bug and pivot into obtaining full control of an operating system or at least gain access to PeopleSoft configuration files, database connection strings, and application data.
On its website, Oracle lists dozens of prominent PeopleSoft users that include government agencies across the U.S. and abroad, healthcare companies and universities. Mandiant urged all organizations to review database logs for any queries about human resources, payroll, and student records tables.
“[ShinyHunters] has a well-established pattern of data theft extortion, that is, stealing data and threatening to release it on a data leak site unless the victim pays a ransom,” Mandiant said. “Affected organizations should prepare for extortion communications and monitor for potential public exposure of stolen data.”
ShinyHunters has claimed dozens of high-profile attacks in recent months and has been in the crosshairs of the FBI for nearly a year after dozens of attacks on large companies like Ticketmaster and AT&T as well as educational publisher McGraw Hill, Carnival Cruise Line, 7-Eleven and other companies.
The group upped the ante last week with its attack on the FBI, providing 5,000-person samples of stolen data to numerous news outlets that confirmed the legitimacy of the data. Samples obtained by Reuters, 404 Media and the BBC contained sensitive medical records, information about secretive FBI units and detailed information on agents.
On Monday, Dutch police said they arrested a 24-year-old suspected member of ShinyHunters from Amsterdam. Cybersecurity reporter Brian Krebs reported the man was a key figure in the group and was locked in a power struggle with another hacker based in Jordan for control of the cybercriminal operation.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



