ShinyHunters Breaches Oracle PeopleSoft Systems, Affecting More Than 100 Organizations
Oracle PeopleSoft is a core ERP platform used by universities, businesses and public-sector bodies to manage human resources, payroll and finances. ShinyHunters targeted CVE-2026-35273, an unauthenticated remote-code-execution flaw, allowing a single zero-day vulnerability to affect institutions worldwide at scale. Data belonging to about 450,000 current and former students at the University of Nottingham was affected, highlighting the risks created when core management systems centralize personal and financial information.
Google Mandiant said the attacks occurred from May 27 to June 9, 2026, and that it notified more than 100 exposed organizations, 68% of them in higher education. The hackers claimed to have compromised about 300 PeopleSoft instances. Oracle issued an emergency patch for the CVSS 9.8 vulnerability on June 10. The hackers claimed to have stolen more than 40GB of data from the University of Nottingham, including payment and credit card information, and demanded an undisclosed ransom.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →