The news
ShinyHunters extortion attacks kept going in late September 2026 even as police closed in on data-theft hackers. On September 25, Google's Mandiant said the group had restarted mass exploitation of an Oracle PeopleSoft flaw, the same day a US court sentenced a separate telecom extortionist.
That sentencing involved Cameron John Wagenius, a 22-year-old former US Army soldier. The Justice Department said he received 70 months in prison and was ordered to pay $294,978 in restitution. Prosecutors said that between April 2023 and December 18, 2024, he conspired with others to defraud at least 10 victim organizations, and that he and his co-conspirators tried to extort at least $1 million from data owners.
In the Netherlands, police said they had arrested a 24-year-old suspected member of ShinyHunters, The Record reported on September 28. KrebsOnSecurity, citing two sources, reported that the man was detained on or around September 16 and had been convicted in 2023 for earlier data thefts and extortions.
The group did not go quiet. KrebsOnSecurity reported that days after the suspect was detained, ShinyHunters claimed a breach of the FBI's job application site. In a memo reported by The New York Times and cited by The Record, FBI officials said they were operating on the premise that personal information of all FBI employees was being exfiltrated.
Mandiant, which tracks the group as UNC6240, said ShinyHunters first exploited CVE-2026-35273 as a zero-day, a flaw attackers use before a fix exists, from May 27 to June 9. Oracle (ORCL) issued a security alert on June 10. In the renewed campaign, Mandiant said the attackers deployed web shells, small programs that give remote control of a server, on dozens of systems globally across higher education, technology, IT services, healthcare, agriculture, transportation and government.
Mandiant said the attackers slipped past web application firewall (WAF) rules by URL-encoding a single character in the request path. Mandiant researcher Austin Larsen told KrebsOnSecurity earlier in September that ShinyHunters was on track to collect nearly $100 million in extortion payments in 2026.
The numbers
- Wagenius prison sentence (DOJ)
- 70 months
- Restitution ordered (DOJ)
- $294,978
- Extortion attempted by Wagenius and co-conspirators (DOJ)
- At least $1 million
- ShinyHunters zero-day exploitation window (Mandiant)
- May 27 to June 9, 2026
- ShinyHunters 2026 extortion pace (Mandiant researcher, via KrebsOnSecurity)
- Nearly $100 million
Why CEOs should care
For CISOs, enforcement headlines should not change the threat model. Mandiant said ShinyHunters adapted to published defensive guidance and went after organizations that applied workarounds but did not patch. Its advice was blunt: "WAF rules and path-based blocking are not a substitute for patching." Ask whether every PeopleSoft instance, including ones run by hosting partners, has the Oracle fix, and whether the Environment Management Hub service is disabled where it is not needed.
For CFOs and boards, the economics matter. If the group is on pace for close to $100 million in payments in 2026, as a Mandiant researcher estimated, extortion is funding its own continuation. Boards should confirm a ransom-payment decision process exists before an incident, that cyber insurance terms cover data-theft extortion as well as encryption attacks, and that outside legal and forensic firms are on retainer. Mandiant said the attackers hunted for HR, payroll and student records, so leaders should know where those tables live.
For HR and security hiring, KrebsOnSecurity reported that the Dutch suspect had worked in offensive security roles after his release from prison in December 2025. That is a reason to review how background checks, access scoping and monitoring apply to security staff and contractors, who often hold the broadest privileges in a company.
The bigger picture
The timelines explain why arrests do little to lower near-term risk. The Wagenius conduct ran from April 2023 to December 2024, his guilty pleas came in 2025, and the sentence arrived in September 2026. By contrast, Mandiant described ShinyHunters returning to the same flaw within months, retooled to get around published defenses. Justice moves in years; attackers retool in months.
The pattern also shows how extortion crews blend social engineering with software flaws. According to KrebsOnSecurity, the February 2026 breach of Dutch telecom Odido began with a lure: a staff member signed in on a counterfeit site, giving ShinyHunters access it then used to take data on more than 6.2 million people. The PeopleSoft campaign relied instead on an unpatched server flaw. Defenses have to cover both routes.
What’s next
Dutch police said the suspect would appear before the Rotterdam District Court on September 29 and that they would release more information then, according to KrebsOnSecurity; no outcome of the hearing had been reported as of September 29. Mandiant urged PeopleSoft customers to apply Oracle's patch, search WebLogic access logs for requests to /PSEMHUB/ and encoded variants such as /%50SEMHUB/, check for unexpected .jsp files, and rotate database and integration credentials. Watch for new victim names on ShinyHunters' leak channels, which would signal whether the renewed campaign has turned into extortion demands.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








