ShinyHunters renews Oracle PeopleSoft attacks with a firewall bypass, Google warns
Google’s threat teams say the extortion group is evading WAF rules to exploit a patched PeopleSoft flaw, while the gang claims it stole FBI employee data.
By Tech CEO Daily Staff, Newsroom
· 2 min read

The news
Mandiant and Google Threat Intelligence Group (GTIG) said on September 25 that the extortion group ShinyHunters, which Google tracks as UNC6240, has launched a new wave of attacks against Oracle PeopleSoft. The activity targets CVE-2026-35273, a remote code execution flaw in PeopleSoft’s Environment Management Hub (PSEMHUB) that the group first exploited as a zero-day between late May and early June. Oracle issued a Security Alert patch on June 10.
According to Google, the attackers have modified their exploit to slip past web application firewall rules by URL-encoding a single character of the vulnerable path. Many WAFs match the literal path before decoding it, so blocks written for the original request miss the altered one. Google said it has seen dozens of compromised systems across higher education, technology, IT services, healthcare, agriculture, transportation and government, with webshells, a backdoor and a legitimate remote-management tool used for persistence.
The campaign overlaps with a high-profile claim. BleepingComputer reported on September 22 that ShinyHunters said it used a PeopleSoft flaw to breach FBI systems and steal 2TB to 3TB of data on employees and job applicants, and that the FBI’s jobs site was defaced. The FBI said it was aware of claims involving FBIjobs.gov and was investigating; it has not confirmed that internal systems were compromised. Help Net Security reported on September 28 that FBI job portals remained offline.
SecurityWeek reported that organisations including Nissan, the University of Nottingham and the insurance regulators’ group NAIC have been linked to the PeopleSoft attacks. Separately, Dutch police confirmed this month’s arrest of a 24-year-old Amsterdam man in a ShinyHunters investigation; the group denied any link to him, BleepingComputer reported.
The numbers
- CVE
- CVE-2026-35273
- Oracle patch released
- June 10, 2026
- Data claimed from FBI (unverified)
- 2–3 TB
Why CEOs should care
Many HR, finance and student systems still run on PeopleSoft, and this group’s playbook is data theft followed by extortion. Ask whether your organisation or any outsourcer runs PeopleSoft, whether the June Security Alert patch is applied, and whether the Environment Management Hub can be disabled, as Google recommends. Do not assume a WAF rule covers you.
Google also advises searching logs for requests to PSEMHUB and its encoded variants, checking for the named webshell files, and rotating credentials available to PeopleSoft service accounts. Prepare the legal and communications team for a possible extortion demand; HR data breaches typically trigger notification duties in many jurisdictions.
The bigger picture
The episode shows how a “fixed” vulnerability can return: a patch closed the flaw, but compensating controls such as firewall rules were easy to sidestep for anyone who had not actually applied it.
Sources
- PrimaryShinyHunters renewed mass exploitation campaign targeting Oracle PeopleSoft— Google Cloud (Mandiant/GTIG)
- ReportShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach— BleepingComputer
- ReportShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks— BleepingComputer
- ReportGoogle Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign— SecurityWeek
- ReportFBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day— Help Net Security
- ReportDutch police confirm arrest in ShinyHunters hacking investigation— BleepingComputer
Newsroom
Reporting and analysis from the Tech CEO Daily newsroom. Each story is researched from primary sources — company announcements, regulatory filings and official advisories — and fact-checked before publication.
Spotted an error? Request a correction. Read our editorial standards and AI policy.
The Daily Brief
The technology briefing for people running businesses.
Weekdays at 6 a.m. ET. Free.


