Mark RadarMARK RADAR
About
EN
Sign in

ShinyHunters Breaches Oracle PeopleSoft Systems, Affecting More Than 100 Organizations

2 reports · First detected 2026-06-11 · Last active 2026-06-12

Oracle PeopleSoft is a core ERP platform used by universities, businesses and public-sector bodies to manage human resources, payroll and finances. ShinyHunters targeted CVE-2026-35273, an unauthenticated remote-code-execution flaw, allowing a single zero-day vulnerability to affect institutions worldwide at scale. Data belonging to about 450,000 current and former students at the University of Nottingham was affected, highlighting the risks created when core management systems centralize personal and financial information.

Google Mandiant said the attacks occurred from May 27 to June 9, 2026, and that it notified more than 100 exposed organizations, 68% of them in higher education. The hackers claimed to have compromised about 300 PeopleSoft instances. Oracle issued an emergency patch for the CVSS 9.8 vulnerability on June 10. The hackers claimed to have stolen more than 40GB of data from the University of Nottingham, including payment and credit card information, and demanded an undisclosed ransom.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)