ShinyHunters targets FBI, 100+ organizations in Oracle PeopleSoft exploits

What sensitive information was leaked due to the Oracle PeopleSoft vulnerability hack?

What risks exist in environments where the patch is not applied?

What security measures are required to prevent incidents like this?


ShinyHunters targets FBI, 100+ organizations in Oracle PeopleSoft exploits
Image source: Unblock Media
  • Group exploits unpatched CVE-2026-35273, defeating new firewall controls and threatening multiple industries.
  • FBI’s recruitment system breach leads to data theft; Google Mandiant and Reuters confirm widespread impact.

On September 25, 2026 (UTC), Google Cloud’s Mandiant reported that ShinyHunters, a resurgent threat group, is actively exploiting a critical unpatched vulnerability—CVE-2026-35273—in Oracle PeopleSoft. This flaw allows remote, unauthenticated code execution. Recent attack waves have bypassed web application firewalls (WAF) and other defenses that organizations deployed after earlier incidents, targeting those that failed to apply Oracle’s official security patch.

Mandiant’s September 25 update highlights that ShinyHunters has adapted its methods following widespread WAF and DDoS mitigation rollouts over the summer. Attackers are circumventing these controls by modifying exploit code and establishing persistence with web shells and backdoors, such as SIDEEYE. The campaign remains active, with global incidents affecting government, healthcare, technology, transportation, and higher education. According to Google, more than 100 affected entities received direct alerts, underscoring the urgent need to patch, investigate systems for compromise, and rotate credentials on exposed networks.

On September 23, 2026, Reuters reported that ShinyHunters successfully breached the FBI’s online recruitment portal during this campaign. The group claims to have stolen 2–3 terabytes of sensitive employee data, including personnel records and assignment information. The FBI confirmed an active investigation and indicated the compromise resulted from the unpatched PeopleSoft bug.

Mandiant warns that firewall or filtering controls alone are insufficient, as attackers are designing exploits to evade detection and take advantage of patch delays, maintaining undetected access to vulnerable servers. Security experts emphasize that immediate patching remains the only effective countermeasure.

Oracle addressed the escalating threat and recent incidents in a September 25, 2026, regulatory filing. Co-founder Larry Ellison increased his Oracle share pledge by 19%, now totaling $9.2 billion, to support a major media acquisition, and canceled a $7.5 billion stock sale after strong Q1 2027 results. Oracle’s revenue grew 30% to $19.3 billion, with market confidence remaining intact after the attacks.

The ongoing exploitation of CVE-2026-35273, confirmed by Mandiant and Reuters, demonstrates the necessity of immediate patch management for Oracle PeopleSoft installations. The FBI’s continuing investigation and broad organizational alerts highlight the severe business and security risk of delaying official security fixes.

telegram

Get real-time crypto breaking news on Unblock Media Telegram! (Click)

Article Info
Category
Tech
Published
2026-09-26 15:11
NFT ID
PENDING
Get the latest news in your inbox!

Recommended News