Skip to content
TECH CEO Daily

ShinyHunters extortion rolls on despite a Dutch arrest as Mandiant flags renewed Oracle PeopleSoft attacks

Police and prosecutors scored visible wins against data-extortion hackers in September 2026, but Mandiant reported on September 25 that ShinyHunters had renewed mass exploitation of an Oracle PeopleSoft flaw.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Mandiant said on September 25 that ShinyHunters restarted mass exploitation of Oracle PeopleSoft flaw CVE-2026-35273.
  • 2Dutch police arrested a suspected ShinyHunters member; in a separate case, a US court sentenced telecom extortionist Cameron Wagenius to 70 months.
  • 3Mandiant says WAF workarounds were bypassed, so unpatched PeopleSoft systems need patching, log reviews and credential rotation.

The news

ShinyHunters extortion attacks kept going in late September 2026 even as police closed in on data-theft hackers. On September 25, Google's Mandiant said the group had restarted mass exploitation of an Oracle PeopleSoft flaw, the same day a US court sentenced a separate telecom extortionist.

That sentencing involved Cameron John Wagenius, a 22-year-old former US Army soldier. The Justice Department said he received 70 months in prison and was ordered to pay $294,978 in restitution. Prosecutors said that between April 2023 and December 18, 2024, he conspired with others to defraud at least 10 victim organizations, and that he and his co-conspirators tried to extort at least $1 million from data owners.

In the Netherlands, police said they had arrested a 24-year-old suspected member of ShinyHunters, The Record reported on September 28. KrebsOnSecurity, citing two sources, reported that the man was detained on or around September 16 and had been convicted in 2023 for earlier data thefts and extortions.

The group did not go quiet. KrebsOnSecurity reported that days after the suspect was detained, ShinyHunters claimed a breach of the FBI's job application site. In a memo reported by The New York Times and cited by The Record, FBI officials said they were operating on the premise that personal information of all FBI employees was being exfiltrated.

Mandiant, which tracks the group as UNC6240, said ShinyHunters first exploited CVE-2026-35273 as a zero-day, a flaw attackers use before a fix exists, from May 27 to June 9. Oracle (ORCL) issued a security alert on June 10. In the renewed campaign, Mandiant said the attackers deployed web shells, small programs that give remote control of a server, on dozens of systems globally across higher education, technology, IT services, healthcare, agriculture, transportation and government.

Mandiant said the attackers slipped past web application firewall (WAF) rules by URL-encoding a single character in the request path. Mandiant researcher Austin Larsen told KrebsOnSecurity earlier in September that ShinyHunters was on track to collect nearly $100 million in extortion payments in 2026.

The numbers

Wagenius prison sentence (DOJ)
70 months
Restitution ordered (DOJ)
$294,978
Extortion attempted by Wagenius and co-conspirators (DOJ)
At least $1 million
ShinyHunters zero-day exploitation window (Mandiant)
May 27 to June 9, 2026
ShinyHunters 2026 extortion pace (Mandiant researcher, via KrebsOnSecurity)
Nearly $100 million

Why CEOs should care

For CISOs, enforcement headlines should not change the threat model. Mandiant said ShinyHunters adapted to published defensive guidance and went after organizations that applied workarounds but did not patch. Its advice was blunt: "WAF rules and path-based blocking are not a substitute for patching." Ask whether every PeopleSoft instance, including ones run by hosting partners, has the Oracle fix, and whether the Environment Management Hub service is disabled where it is not needed.

For CFOs and boards, the economics matter. If the group is on pace for close to $100 million in payments in 2026, as a Mandiant researcher estimated, extortion is funding its own continuation. Boards should confirm a ransom-payment decision process exists before an incident, that cyber insurance terms cover data-theft extortion as well as encryption attacks, and that outside legal and forensic firms are on retainer. Mandiant said the attackers hunted for HR, payroll and student records, so leaders should know where those tables live.

For HR and security hiring, KrebsOnSecurity reported that the Dutch suspect had worked in offensive security roles after his release from prison in December 2025. That is a reason to review how background checks, access scoping and monitoring apply to security staff and contractors, who often hold the broadest privileges in a company.

The bigger picture

The timelines explain why arrests do little to lower near-term risk. The Wagenius conduct ran from April 2023 to December 2024, his guilty pleas came in 2025, and the sentence arrived in September 2026. By contrast, Mandiant described ShinyHunters returning to the same flaw within months, retooled to get around published defenses. Justice moves in years; attackers retool in months.

The pattern also shows how extortion crews blend social engineering with software flaws. According to KrebsOnSecurity, the February 2026 breach of Dutch telecom Odido began with a lure: a staff member signed in on a counterfeit site, giving ShinyHunters access it then used to take data on more than 6.2 million people. The PeopleSoft campaign relied instead on an unpatched server flaw. Defenses have to cover both routes.

What’s next

Dutch police said the suspect would appear before the Rotterdam District Court on September 29 and that they would release more information then, according to KrebsOnSecurity; no outcome of the hearing had been reported as of September 29. Mandiant urged PeopleSoft customers to apply Oracle's patch, search WebLogic access logs for requests to /PSEMHUB/ and encoded variants such as /%50SEMHUB/, check for unexpected .jsp files, and rotate database and integration credentials. Watch for new victim names on ShinyHunters' leak channels, which would signal whether the renewed campaign has turned into extortion demands.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

ShinyHuntersMandiantOracleData extortionCybercrime enforcement

Earlier coverage of Oracle

All Oracle coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.