Skip to content
Tech CEO Daily

ShinyHunters renews Oracle PeopleSoft attacks with a firewall bypass, Google warns

Google’s threat teams say the extortion group is evading WAF rules to exploit a patched PeopleSoft flaw, while the gang claims it stole FBI employee data.

TC

By Tech CEO Daily Staff, Newsroom

· 2 min read

A dim office at night with an HR and payroll database on a monitor
AI-generated image for illustration. Not a photograph of the events described.

The news

Mandiant and Google Threat Intelligence Group (GTIG) said on September 25 that the extortion group ShinyHunters, which Google tracks as UNC6240, has launched a new wave of attacks against Oracle PeopleSoft. The activity targets CVE-2026-35273, a remote code execution flaw in PeopleSoft’s Environment Management Hub (PSEMHUB) that the group first exploited as a zero-day between late May and early June. Oracle issued a Security Alert patch on June 10.

According to Google, the attackers have modified their exploit to slip past web application firewall rules by URL-encoding a single character of the vulnerable path. Many WAFs match the literal path before decoding it, so blocks written for the original request miss the altered one. Google said it has seen dozens of compromised systems across higher education, technology, IT services, healthcare, agriculture, transportation and government, with webshells, a backdoor and a legitimate remote-management tool used for persistence.

The campaign overlaps with a high-profile claim. BleepingComputer reported on September 22 that ShinyHunters said it used a PeopleSoft flaw to breach FBI systems and steal 2TB to 3TB of data on employees and job applicants, and that the FBI’s jobs site was defaced. The FBI said it was aware of claims involving FBIjobs.gov and was investigating; it has not confirmed that internal systems were compromised. Help Net Security reported on September 28 that FBI job portals remained offline.

SecurityWeek reported that organisations including Nissan, the University of Nottingham and the insurance regulators’ group NAIC have been linked to the PeopleSoft attacks. Separately, Dutch police confirmed this month’s arrest of a 24-year-old Amsterdam man in a ShinyHunters investigation; the group denied any link to him, BleepingComputer reported.

The numbers

CVE
CVE-2026-35273
Oracle patch released
June 10, 2026
Data claimed from FBI (unverified)
2–3 TB

Why CEOs should care

Many HR, finance and student systems still run on PeopleSoft, and this group’s playbook is data theft followed by extortion. Ask whether your organisation or any outsourcer runs PeopleSoft, whether the June Security Alert patch is applied, and whether the Environment Management Hub can be disabled, as Google recommends. Do not assume a WAF rule covers you.

Google also advises searching logs for requests to PSEMHUB and its encoded variants, checking for the named webshell files, and rotating credentials available to PeopleSoft service accounts. Prepare the legal and communications team for a possible extortion demand; HR data breaches typically trigger notification duties in many jurisdictions.

The bigger picture

The episode shows how a “fixed” vulnerability can return: a patch closed the flaw, but compensating controls such as firewall rules were easy to sidestep for anyone who had not actually applied it.

Sources

TC
Tech CEO Daily Staff

Newsroom

Reporting and analysis from the Tech CEO Daily newsroom. Each story is researched from primary sources — company announcements, regulatory filings and official advisories — and fact-checked before publication.

Spotted an error? Request a correction. Read our editorial standards and AI policy.

The Daily Brief

The technology briefing for people running businesses.

Weekdays at 6 a.m. ET. Free.

More in Cybersecurity