
The vulnerability in Oracle’s PeopleSoft software is about as severe as it gets.
One of the most prolific ransomware groups in the world exploited a critical flaw in Oracle’s PeopleSoft suite, targeting roughly 100 customers and extorting at least one of them into paying a ransom to prevent the release of stolen data, according to researchers.
The group, known as ShinyHunters, had been leveraging the PeopleSoft vulnerability for over two weeks before Oracle flagged it. Tracked as CVE-2026-35273, the flaw carries a severity score of 9.8 out of 10, making the former zero-day one of the most critical vulnerabilities exploited this year.
Google’s Mandiant security team described it as an SSRF (server-side request forgery), a type of vulnerability that enables attackers to send requests from a susceptible server to systems used by the targeted organization. Oracle noted that the SSRF is remotely exploitable and has issued a temporary mitigation but has not yet fully patched the flaw. Google has confirmed that victims are receiving extortion demands.
9.8 0-day exploited for two weeks
The University of Nottingham confirmed on Wednesday that it had been hacked, resulting in a “significant” amount of student data falling into the hands of a threat actor. This confirmation came after ShinyHunters claimed the university was one of its recent victims and published gigabytes of data it alleged to have stolen in the breach.
Mandiant stated that ShinyHunters has been exploiting the vulnerability since May 27. As of Wednesday, the group had targeted approximately 300 endpoints across 100 user organizations. About 68 percent of these organizations were in the higher education sector. A researcher noted on Tuesday that the responsible group had “exposed several directories revealing ongoing targeting of PeopleSoft.” The attackers also left a staging server containing tools used in the attack.
“While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters DLS,” Mandiant said. (DLS stands for data leak site.)
An analysis of a bash script left in the staging environment revealed that the attackers conducted reconnaissance on compromised organizations, including mapping PeopleSoft configurations, viewing process scheduler, and WebLogic server XML configurations. Eventually, the threat actors established an outbound SSH connection to 176.120.22.24, the IP address hosting ShinyHunters’ DLS. The stolen data was first compressed using the zstd tool. The DLS claimed to have recovered 48GB of data from a single victim.
ShinyHunters has been active since at least 2019. Over the past several years, it has carried out numerous hacks against some of the world’s largest companies, affecting millions of people downstream. A small sample of victims includes Ticketmaster (via the breach of Snowflake, which hosted the data), Spain’s largest bank, Santander, and Salesforce (and, through it, Google and, reportedly, many other companies). ShinyHunters uses various techniques to gain initial access, including exploiting cloud misconfigurations and software vulnerabilities, stealing OAuth tokens, supply chain attacks, voice phishing, and other forms of social engineering.
Mandiant and Rapid7 are providing detailed indicators of compromise. They are also advising PeopleSoft customers on the steps they should take immediately. Given ShinyHunters’ success rate, all PeopleSoft users would do well to heed the calls.