The ivory tower has never felt more vulnerable. In one of the most aggressive and precisely targeted cyberattack campaigns of 2026, the prolific extortion group ShinyHunters has rampaged through more than 100 organisations — and universities are squarely in the crosshairs. By exploiting a previously unknown, critical zero-day vulnerability in Oracle's widely-used PeopleSoft platform, the group has stolen sensitive student records, threatened institutions with public data leaks, and exposed a gaping blind spot in how higher education manages cybersecurity risk.
If your institution runs Oracle PeopleSoft, this is not background reading — it's an urgent briefing. Here's everything you need to know about what happened, who is behind it, and what you can do right now.
What Happened: The ShinyHunters Oracle PeopleSoft Campaign
From May 27 to June 9, 2026, the ShinyHunters extortion gang exploited a zero-day vulnerability in PeopleTools, PeopleSoft's underlying integrated development environment and runtime platform, according to new research from Mandiant and the Google Threat Intelligence Group (GTIG).
The activity involved the exploitation of a critical zero-day flaw tracked as CVE-2026-35273, with a near-maximum CVSS score of 9.8, to compromise university networks.
To put that score in context: a 10.0 is as dangerous as vulnerabilities get.
The flaw is a remote code execution vulnerability in Oracle PeopleSoft's Environment Management component — rated 9.8 out of 10 — and requires no authentication whatsoever.
That means an attacker anywhere in the world could walk directly into a vulnerable PeopleSoft server without needing a username or password.
Because this activity predates Oracle's June 10, 2026 advisory, the vulnerability was exploited as a zero-day, meaning every organisation struck during those two weeks had no available patch and no official vendor warning.
The threat actors concluded their campaign on June 9 by leaking their winnings on their website. At that point, researchers from TrendAI identified the vulnerability and alerted Oracle, who patched the flaw and published a security advisory the following day.
The Scale of the Attack and Who Was Hit
The impact of this campaign is staggering in both breadth and focus.
Google's researchers notified more than 100 global organisations of potential exposure, the majority of which are based in the US, with 68% in the higher education sector. Some of the targets blocked the attack, but others had their systems compromised and data stolen. ShinyHunters claims to have targeted roughly 300 PeopleSoft instances belonging to 100 organisations.
The University of Nottingham in the UK has confirmed that it was one of the fallen, having lost "a significant amount of data" from its student records system — acknowledging that both current and former students were impacted, though not indicating what specific kinds of data were stolen.
On its dark web leak site, ShinyHunters listed the University of Nottingham as a recent victim, alleging it possessed more than 40 GB of sensitive data.
How the Attackers Moved Inside Systems
The technical sophistication of the operation is notable.
CVE-2026-35273 is an unauthenticated remote code execution bug in Oracle PeopleSoft PeopleTools (mainly versions 8.61 and 8.62) in the Environment Management Hub component. This bug allowed hackers to bypass authentication entirely or log in as privileged users. Instead of a direct database exploit, they operated entirely inside PeopleSoft's application logic, using legitimate APIs to access and extract records — meaning standard database security monitors never noticed anything was wrong.
Researchers found that the attackers hosted customised MeshCentral agents disguised as legitimate cloud endpoints, which were used to run administrative command queries. These agents were deployed via attacker-controlled staging infrastructure using binaries impersonating cloud services and connected back to a command-and-control domain designed to mimic Microsoft Azure infrastructure.
A script named after each victim spread over SSH by spraying a hardcoded list of usernames and passwords against internal hosts, then dropped a marker file into PeopleSoft directories.
The audacity of leaving a named file behind underscores the group's confidence — and their contempt for victim organisations.
Who Are ShinyHunters? A Criminal Empire in Full Swing
To understand why this attack matters so much, you need to understand who ShinyHunters are — and how far their reach extends.
ShinyHunters is a black-hat criminal hacker and extortion group believed to have formed as early as 2019. The group operates under the leadership of a persona known as ShinyCorp. Their motive is financial, and their operating model follows a simple, brutal pipeline: breach, exfiltrate data, issue a ransom demand, and publish or auction the data if payment is refused.
Using three attack playbooks — voice phishing for SSO credentials, Salesforce Experience Cloud misconfigurations, and OAuth supply chain attacks — they have executed the most devastating data theft campaign in history across 2025–2026.
Confirmed victims include Canvas/Instructure (275 million students), Carnival (6 million passengers), ADT (5.5 million customers), Charter Communications (4.9 million), Kemper (13 million), McGraw-Hill (13.5 million), Rockstar Games (78.6 million), Telus (1+ petabyte), and the European Commission.
Crucially, the education sector has been a repeated target.
Over the past couple of months, the collective has been targeting education institutions specifically, and the PeopleSoft attacks follow swiftly on the heels of its April compromise of Instructure's Canvas learning management system, in which ShinyHunters claimed to have exfiltrated 3.65TB of data comprising 275 million records from almost 9,000 different institutions.
Four members were arrested in France in June 2025 — and the group kept operating.
This is not a group that is deterred easily.
Why Higher Education Is Such a Prime Target
Universities represent a uniquely attractive combination of rich data and relatively limited defences.
Unlike traditional corporations, universities operate massive and highly decentralised digital environments, with thousands of students, faculty members, researchers, and administrators accessing systems every day from countless devices and locations — while at the same time storing enormous amounts of valuable information.
In many cases, a university's data holdings rival those of large corporations — yet their cybersecurity budgets often do not. That imbalance creates opportunities for sophisticated threat actors looking for maximum leverage with minimum resistance.
PeopleSoft is an enterprise resource planning (ERP) application suite used for things like payroll, supply chain management, human resources, and student administration — and it is primarily oriented to large businesses and organisations such as government entities and higher education institutions.
The concentration of PeopleSoft deployments within the higher education sector effectively turned every vulnerable instance into a target waiting to be found.
The attacks come less than a year after the Clop ransomware group exploited a zero-day in Oracle E-Business Suite that affected dozens of victims
— a pattern that signals cybercriminals increasingly view Oracle's enterprise education software stack as fertile ground for large-scale extortion.
Oracle's Response: An Emergency Out-of-Band Patch
Oracle acted swiftly once the exploitation was disclosed — but the damage had already been done during the two-week window before the advisory.
Oracle issued an out-of-band Security Alert on June 10, 2026, for CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in PeopleSoft PeopleTools 8.61 and 8.62. Administrators must apply the emergency patch immediately or isolate affected systems to prevent active exploitation that can lead to data theft and Windows domain compromise.
Oracle normally adheres to a strict quarterly patch schedule — January, April, July, and October. The issuance of a Security Alert outside this cycle, known as an "out-of-band" patch, happens only when a vulnerability is being actively attacked or is so critical it cannot wait.
Oracle considers implementation of the recommended mitigations to be a high-priority risk reduction measure and strongly recommends immediate action to address the identified exposure.
Only versions 8.61 and 8.62 under Premier or Extended Support are eligible for patches; unsupported versions remain vulnerable and should be decommissioned or isolated.
Practical Tips: What Your Institution Should Do Right Now
If your institution uses Oracle PeopleSoft, complacency is not an option. Here is an actionable checklist based on guidance from Rapid7, SOCRadar, Oracle, and Horizon3:
1. Apply Oracle's Emergency Patch Immediately
Apply Oracle's security update and recommended mitigations immediately. Oracle advises customers running unsupported PeopleTools versions to upgrade to a supported release as soon as possible.
2. Assume Compromise If You Were Exposed Between May 27–June 9
If the system was exposed between May 27 and June 9, 2026, administrators should preserve logs and assess the environment as a potential compromise case — not merely as a missing patch.
3. Audit Your Entire PeopleSoft Footprint
Administrators should validate the installed PeopleTools version and patch state across production, disaster recovery, staging, and forgotten development instances. The hidden danger in PeopleSoft estates is usually not the server everyone knows about — it is the old endpoint still reachable because a workflow, integration, or department portal would break if someone removed it.
4. Restrict Network Exposure Immediately
Network exposure should be minimised by restricting HTTP/HTTPS access to PeopleSoft endpoints from untrusted networks and implementing robust firewall rules.
5. Monitor for Suspicious Outbound Traffic
Monitor outbound SMB traffic (TCP port 445) from PeopleSoft servers to untrusted external destinations. Given that exploitation occurred as early as May 27, 2026, Rapid7 strongly recommends investigating for signs of compromise even after patching, using the indicators of compromise outlined by Mandiant.
6. Check for the Attacker's Marker File
Forensic teams should scan PeopleSoft directories for the file README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT —
dropped by the attackers' lateral-movement script as part of their post-exploitation routine.
7. Plan for the Broader Threat Picture
The open question is whether this was a one-off borrowed zero-day or the start of ShinyHunters moving into ERP exploitation.
IT and security teams should not treat this as an isolated event. Continuous vulnerability monitoring, regular ERP security assessments, and threat intelligence feeds tuned to ShinyHunters activity should be standard practice going forward.
Conclusion: The Education Sector Must Raise Its Defences
The ShinyHunters Oracle PeopleSoft campaign is a watershed moment for cybersecurity in higher education. It demonstrates that sophisticated, financially motivated threat actors are no longer content with opportunistic attacks — they are systematically identifying the enterprise software platforms that universities depend on, discovering or acquiring zero-day vulnerabilities, and executing precision campaigns before defenders even know there is a hole to plug.
A vulnerability in one critical platform can create ripple effects across hundreds of institutions. The Oracle PeopleSoft incident demonstrates how quickly a single weakness can become a widespread security problem. For universities, businesses, and government organisations alike, cybersecurity is no longer just an IT responsibility — it has become a core organisational risk.
The patch is now available. The indicators of compromise are public. The question is whether your institution will act with the urgency this threat demands — or become the next name on ShinyHunters' dark web leak site.
Is your institution's Oracle PeopleSoft environment fully patched and assessed? Now is the time to find out. Engage your IT security team today, commission an immediate vulnerability assessment of all ERP infrastructure, and ensure your incident response plan is updated to account for zero-day exploitation scenarios. The cost of inaction — in data, in reputation, and in student trust — is simply too high.



