ThinkPatternGet the app
Story
TECHNOLOGY · SEP 26, 2026

ShinyHunters Exploit Oracle PeopleSoft Flaw to Target Global Sectors

The hacking group ShinyHunters exploited a security flaw in Oracle PeopleSoft software to target dozens of global organizations and claim a breach of FBI personnel data.

The hacking group ShinyHunters has launched a renewed wave of mass exploitations targeting a security vulnerability in Oracle's PeopleSoft enterprise software. According to a report from Mandiant, Google's cybersecurity unit, the group previously targeted universities in late May and early June before adapting its methods to bypass web application firewall rules in organizations that had not applied Oracle's official patch.

The latest attacks have affected dozens of global systems across the healthcare, technology, government, agriculture, transportation, and higher education sectors. As part of this campaign, ShinyHunters claims to have stolen personnel data from the Federal Bureau of Investigation, specifically targeting medical and psychiatric records of staff serving in sensitive units.

The Federal Bureau of Investigation is currently investigating the reported breach, although the claim that its data was stolen remains uncorroborated.


Reported across 5 outlets
Actors
Oracle Corporation

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play