ShinyHunters Hits 100+ Organisations Through Oracle PeopleSoft
The ShinyHunters extortion gang is back — and this time they went after the back office.
Oracle PeopleSoft, an enterprise software suite used by large organisations to manage payroll, HR, finance, and supply chain operations, is being targeted in an active data theft campaign, according to BleepingComputer. ShinyHunters claims to have stolen data from 300 instances across more than 100 organisations, and affected customers are already receiving extortion demands.
The attackers say they are chaining old and zero-day vulnerabilities together to gain access — though they note the method does not work on every system, suggesting configuration or version differences affect their success rate.
What makes this particularly sensitive is the kind of data PeopleSoft holds. This is not a list of email addresses. HR and payroll systems store names, national ID numbers, salary records, and employment histories. If your employer uses PeopleSoft — especially in a university, government body, or large enterprise — your personal data may be in scope.
No CVE identifiers have been confirmed in the source material at the time of writing. ShinyHunters has not disclosed the specific vulnerabilities used publicly.
What you should do: If you work in IT at an organisation running Oracle PeopleSoft, check with your vendor contact for guidance and monitor for extortion-related communications. If you are an employee at a large organisation, watch for phishing attempts that reference your employer or personal employment details — this is exactly the kind of data that fuels targeted scams.
Sources

