Login Start Free Trial

Oracle Warns Customers After PeopleSoft Flaw Is Linked to Widespread Hacking Campaign

Oracle has warned customers to take immediate action after a critical flaw in its PeopleSoft software was linked to a widespread hacking and extortion campaign.

The vulnerability, tracked as CVE-2026-35273, affects Oracle PeopleSoft PeopleTools, a platform used by many large organizations to manage business systems such as human resources, finance and administration. Oracle said the flaw can be exploited remotely without authentication, meaning attackers may not need valid login credentials to target vulnerable systems.

Google’s Mandiant and Google Threat Intelligence Group said attackers exploited the flaw between May 27 and June 9, 2026, before Oracle issued its June 10 security alert. The activity was linked by Google to ShinyHunters, a cybercriminal group known for data theft and extortion campaigns.

The campaign reportedly affected more than 100 organizations. Researchers said a large share of the identified victims were in the higher education sector, where PeopleSoft is commonly used to manage student, employee and financial records.

Oracle Issues Alert as Researchers Report Active Exploitation

According to Oracle, the vulnerability is considered critical because it can allow remote code execution in affected PeopleSoft systems. Remote code execution means attackers may be able to run commands on a vulnerable server, which can give them a path to steal data, deploy tools or move deeper into a network.

Oracle issued a security alert on June 10 and urged customers to follow its recommended mitigation steps. The company said customers should act quickly to reduce the risk of compromise.

Google’s researchers said the flaw had already been abused before Oracle’s alert. That makes the incident especially serious for organizations that had exposed PeopleSoft systems connected to the internet during the reported attack window.

Because the exploitation reportedly took place before the public advisory, security teams may need to do more than apply mitigations. They may also need to investigate whether attackers had already accessed their systems before protections were put in place.

Google Links the Campaign to ShinyHunters Activity

Google attributed the activity to ShinyHunters, a group associated with previous data theft and extortion campaigns. The researchers said the attackers targeted vulnerable PeopleSoft instances and used them as part of a broader effort to steal information and pressure victims.

The attackers reportedly used disguised MeshCentral agents during the campaign. MeshCentral is a legitimate remote management tool, but cybercriminals can misuse such tools to maintain access to compromised systems. In this case, researchers said the software was made to appear like legitimate cloud-related infrastructure, which could help attackers avoid detection.

According to reports, some victims received extortion emails claiming that sensitive data had been stolen. The claimed information included student-related records such as names, contact details, birth dates and enrollment information. These claims remain reported allegations unless confirmed by each affected organization.

Google said it notified more than 100 organizations whose systems appeared to be connected to the campaign. Reports also said attackers may have accessed nearly 300 PeopleSoft instances, though the final number of confirmed breaches may change as investigations continue.

Higher education appears to have been a major target. Reuters reported that about 68% of identified victims were in the education sector. Universities and colleges often store large amounts of personal and administrative data, making them attractive targets for cybercriminal groups seeking leverage for extortion.

What Affected Organizations Should Do

Organizations using Oracle PeopleSoft should review Oracle’s June 10 security alert and apply the recommended mitigations as soon as possible. Security teams should also review activity logs from late May through early June, especially the period between May 27 and June 9, when researchers said exploitation occurred.

Important signs to check include unusual administrative commands, suspicious remote access tools, new or unexpected accounts, and unusual connections from PeopleSoft servers. Organizations should also look for evidence of data access or data transfer, especially if their systems were exposed to the internet during the attack period.

The incident is a reminder that patching or mitigation may not be enough when attackers exploit a vulnerability before public disclosure. If a system was already compromised, attackers may have installed tools, created access paths or taken data before the organization became aware of the issue.

PeopleSoft customers should work with internal security teams or incident response experts if they suspect unauthorized access. Organizations that confirm data theft may also need to notify affected individuals, regulators or other authorities depending on the type of data involved and local breach notification requirements.

The case highlights the ongoing risk around widely used enterprise software. When critical flaws affect systems used across universities, businesses and government-linked organizations, attackers can move quickly to scan the internet and target exposed servers.

For now, Oracle customers are being urged to take the alert seriously, apply mitigations and investigate whether their systems were accessed during the reported exploitation window. The wider impact of the campaign will become clearer as affected organizations complete their reviews and confirm whether data was stolen.

Browse

Related Article