ShinyHunters breach 100+ orgs via Oracle PeopleSoft flaw
A criminal group known as ShinyHunters exploited a critical unpatched flaw in Oracle PeopleSoft software to break into more than 100 organizations, most of them universities, before Oracle issued an emergency patch. Confirmed victims include the insurance regulator group NAIC and carmaker Nissan, whose current and former employee data was stolen. Oracle's July security update addressed the flaw further, but only a small number of the 100-plus targeted organizations have been publicly confirmed so far.
- Started
- Aug 9, 2025
- Latest activity
- Aug 18, 2026
- Attributed to
- ShinyHuntersLikely
- Where
- United States, Japan
- Sectors
- Education, Finance, Manufacturing, Government, Retail, Multiple sectors +2
- Scale
- more than 100 organizations targeted, about two thirds of them universities, with only a handful publicly confirmed
Current status
After July 29, reporting showed ShinyHunters remained active in separate attacks, but no credible PeopleSoft-specific activity or new confirmed PeopleSoft victims was reported through September 8, 2026.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Who is behind it
Security researchers and multiple outlets, citing Google-owned threat intelligence, linked the campaign to the ShinyHunters extortion group; the group itself has also claimed some of the thefts.
Impact
Attackers stole data from breached organizations before Oracle patched the flaw. Nissan confirmed theft of current and former employee data. NAIC confirmed theft of public financial reports, credit rating data, and some technical files, but did not confirm the attacker's claim of taking 3.1 TB. NAIC said on August 18 that all needed credit rating feeds had returned and related investment ratings were being published again.
What to do
PeopleSoft administrators should confirm Oracle's emergency and July patches are installed and watch for notification letters if they work for or attended an affected organization.
Timeline
-
Sep 8, 2026
BleepingComputer reported that ShinyHunters claimed access to a Florida DMV database. Florida officials had not confirmed the breach, and no link to the PeopleSoft campaign was reported.
Containedbleepingcomputer.com -
Sep 7, 2026
CPO Magazine reported that ShinyHunters claimed a Carhartt breach affecting nearly 13 million people. The report did not link it to the Oracle PeopleSoft campaign.
Containedcpomagazine.com -
Aug 28, 2026
McKesson disclosed unauthorized access to third-party applications after ShinyHunters claimed patient-data theft. The reporting did not link the incident to the Oracle PeopleSoft campaign.
Containedbleepingcomputer.com -
Aug 18, 2026
NAIC said it was receiving all needed credit rating feeds and had resumed publishing related investment ratings on August 17.
Containedcontent.naic.org -
Aug 10, 2026
NAIC said all credit rating provider feeds needed for its filing exempt process had resumed.
Containedcontent.naic.org -
Aug 10, 2026
NAIC said all credit rating provider data feeds needed for its filing exempt process, which had been paused since the breach, had resumed.
Containedcontent.naic.org -
Aug 4, 2026
A security outlet reported the Brinks Home breach and an earlier ADT breach were carried out by the same group using a phone call to trick an employee rather than malware, though this specific claim has not been confirmed by either company.
Activekomando.com -
Aug 4, 2026
Brinks Home refused to pay the ransom, and ShinyHunters leaked roughly 41 gigabytes of the stolen customer data online, including real support conversation records.
Active -
Aug 2, 2026
Security researchers reported a wave of fake extortion emails signed with the ShinyHunters name, including one using data from the unrelated April 2026 Carnival Corporation breach, demanding $2,000 in Litecoin from people who were never actually breached by the group.
Activebleepingcomputer.com -
Aug 1, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Jul 31, 2026
Brinks Home confirmed the breach and further coverage described hackers leaking files, with customer contact information and millions of chat logs among the data potentially exposed.
Activeinc.com -
Jul 30, 2026
Brinks Home Security disclosed it found unauthorized system access on July 20; ShinyHunters claimed to have stolen about 4.9 million Salesforce records and threatened to publish them, while Brinks Home said its alarm monitoring and customer service stayed operational.
Activebleepingcomputer.com -
Jul 29, 2026
Health-ISAC warned healthcare and medical technology organizations of a rise in successful ShinyHunters data theft attacks.
Activebleepingcomputer.com -
Jul 27, 2026
Ernst & Young's data breach, disclosed publicly this day, was claimed by ShinyHunters, which said it got credentials for some EY systems through a supply-chain attack and threatened to leak the data if not paid by month's end.
Activebleepingcomputer.com -
Jul 27, 2026
Coverage of the campaign's scope continued to run, with ShinyHunters still listing new named victims and leaked data.
Activemartincid.com -
Jul 22, 2026
The Next Web reported that Estee Lauder's disclosure involved a separate August 2025 Oracle E-Business Suite breach linked to Clop, not the 2026 ShinyHunters PeopleSoft campaign.
Containedthenextweb.com -
Jul 21, 2026
Oracle's July Critical Patch Update fixed the PeopleSoft flaw chain that ShinyHunters used to breach roughly 300 servers across 100-plus organizations.
Containedtechtimes.com -
Jul 21, 2026
Oracle's July critical patch update closed the exploited flaw, and Estee Lauder disclosed that customer and employee data was taken from its Oracle E-Business Suite HR system.
Containedsecurityweek.com -
Jul 21, 2026
Oracle closed the PeopleSoft/E-Business Suite flaw chain in a record-sized July Critical Patch Update, and Estee Lauder confirmed attackers had taken personal, financial, and health data dating back to an August 2025 intrusion.
Containedsecurityweek.com -
Jul 21, 2026
Oracle's July Critical Patch Update closed the exploited PeopleSoft/EBS flaw chain, and Estee Lauder detailed the personal, financial, and health data taken from its systems.
Containedsecurityweek.com -
Jul 21, 2026
Estee Lauder disclosed a data breach tied to the Oracle E-Business Suite flaw, and Oracle released its July Critical Patch Update closing the exploited flaws.
Containedtechtimes.com -
Jul 21, 2026
Oracle's July Critical Patch Update further addressed the PeopleSoft exploit chain used in the breaches.
Containedtechtimes.com -
Jul 16, 2026
CISA ordered US federal agencies to patch the actively exploited Oracle E-Business Suite flaw by that Saturday.
Activebleepingcomputer.com -
Jul 16, 2026
CISA ordered US federal agencies to patch the actively exploited Oracle EBS flaw by that Saturday.
Activebleepingcomputer.com -
Jul 16, 2026
CISA added the Oracle E-Business Suite flaw to its known exploited vulnerabilities list and ordered federal agencies to patch within days.
Activebleepingcomputer.com -
Jun 30, 2026
Nissan disclosed that current and former employee data was stolen via the same campaign.
Activesecurityweek.com -
Jun 30, 2026
Nissan and Estee Lauder disclosed employee and HR data theft tied to the same Oracle PeopleSoft campaign, with reporting noting only a handful of the 100-plus targeted organizations confirmed so far.
Activesecurityweek.com -
Jun 30, 2026
Nissan and Estee Lauder disclosed employee and customer data theft tied to the same Oracle flaw campaign.
Activebleepingcomputer.com -
Jun 30, 2026
SecurityWeek reported that only a handful of the roughly 100 organizations ShinyHunters claims to have hit had been publicly confirmed.
Activesecurityweek.com -
Jun 30, 2026
SecurityWeek reported only a handful of the roughly 100 targeted organizations had been publicly confirmed.
Activesecurityweek.com -
Jun 29, 2026
NAIC said the stolen data from its breach was limited to public information, outdated logs, and configuration files.
Activebleepingcomputer.com -
Jun 29, 2026
The NAIC, the US insurance regulators' association, confirmed its systems were breached through the same Oracle flaw.
Activeinfosecurity-magazine.com -
Jun 29, 2026
NAIC confirmed attackers exploited an Oracle PeopleSoft zero-day and the ShinyHunters group claimed to have stolen 3.1 TB of data.
Emergingsecurityweek.com -
Jun 29, 2026
NAIC confirmed attackers used a PeopleSoft zero-day to access its systems; CISA added the related Oracle EBS flaw CVE-2026-46817 to its Known Exploited Vulnerabilities catalog the same day.
Activeinfosecurity-magazine.com -
Jun 29, 2026
The National Association of Insurance Commissioners confirmed a breach, with ShinyHunters claiming 3.1 TB of stolen data.
Activesecurityweek.com -
Jun 29, 2026
The insurance regulators group NAIC confirmed a breach, with ShinyHunters claiming 3.1 TB of stolen data; separately, attackers began exploiting a new Oracle E-Business Suite flaw.
Activesecurityweek.com -
Jun 29, 2026
NAIC confirmed ShinyHunters stole an estimated 3.1 TB of data from its systems.
Activesecurityweek.com -
Jun 17, 2026
Kodak confirmed a data breach after ShinyHunters claimed to have stolen 2.2 million records.
Activebleepingcomputer.com -
Jun 17, 2026
Nissan disclosed that current and former employee data was stolen in an attack linked to the PeopleSoft campaign.
Activebleepingcomputer.com -
Jun 17, 2026
Nissan disclosed a data breach of current and former employee data linked to the Oracle PeopleSoft attacks.
Activebleepingcomputer.com -
Jun 17, 2026
Nissan disclosed that current and former employee data was stolen in the campaign.
Activebleepingcomputer.com -
Jun 16, 2026
Reports put the flaw, CVE-2026-35273 with a 9.8 severity score, behind more than 100 breaches with no patch yet available.
Activetechtimes.com -
Jun 12, 2026
Oracle issued an out-of-band emergency patch for the PeopleSoft PeopleTools flaw.
Activecomputerweekly.com -
Jun 11, 2026
Google's Mandiant and Threat Intelligence Group said ShinyHunters was actively exploiting an Oracle PeopleSoft flaw to breach organizations, mostly universities.
Emergingreuters.com -
Jun 11, 2026
Oracle confirmed and issued mitigation guidance for the critical PeopleSoft flaw, tracked as CVE-2026-35273, that was being actively exploited.
Activebleepingcomputer.com -
Jun 11, 2026
Oracle issued an out of band fix for the PeopleSoft zero day, tracked as CVE-2026-35273, after confirming active exploitation.
Activebleepingcomputer.com -
Jun 11, 2026
Researchers said ShinyHunters had exploited CVE-2026-35273 to breach over 100 organizations, mostly universities.
Activethenextweb.com -
Jun 10, 2026
ShinyHunters told TechCrunch it had breached Oracle PeopleSoft servers at more than 100 organizations, mostly universities.
Emergingtechcrunch.com -
Jun 10, 2026
BleepingComputer reported ShinyHunters actively stealing data from Oracle PeopleSoft servers, claiming over 100 organizations hit.
Emergingbleepingcomputer.com -
Jun 10, 2026
ShinyHunters began claiming theft of data from Oracle PeopleSoft servers at more than 100 organizations.
Emergingbleepingcomputer.com -
Jun 10, 2026
BleepingComputer reported that ShinyHunters was exploiting an Oracle PeopleSoft zero-day to steal data from over 100 organizations.
Emergingbleepingcomputer.com -
May 31, 2026
Reports emerged that a zero-day flaw in Oracle PeopleSoft was being exploited in a widespread attack.
Emergingyahoo.com
Sources
- Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack SecurityWeek Jun 29, 2026
- Nissan discloses employee data breach linked to Oracle zero-day attacks BleepingComputer Jun 17, 2026
- Nissan Employee Data Breached in Oracle PeopleSoft Hack SecurityWeek Jun 30, 2026
- ShinyHunters breached 100+ companies through an unpatched Oracle PeopleSoft zero-day The Next Web Jun 11, 2026
- Oracle fixes PeopleSoft flaw exploited by ShinyHunters Computer Weekly Jun 12, 2026
- A 9.8/10 Oracle PeopleSoft flaw gave ShinyHunters two weeks in 100+ organizations Martin Cid Magazine Jul 27, 2026
- PeopleSoft Exploit Behind 100+ Breaches Gets Patched in Oracle's Record July CPU Tech Times Jul 21, 2026
- Nissan employee data stolen via Oracle PeopleSoft flaw NeuraCybIntel Jun 30, 2026
- Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks BleepingComputer Jun 10, 2026
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks BleepingComputer Jun 11, 2026
- US insurance regulator hit by Oracle breach Infosecurity Magazine Jun 29, 2026
- Nissan employee data stolen via Oracle hack Infosecurity Magazine Jun 30, 2026
- CISA orders feds to patch actively exploited Oracle flaw by Saturday BleepingComputer Jul 16, 2026
- Estee Lauder Discloses Impact From Oracle EBS Zero-Day Hack SecurityWeek Jul 21, 2026
- Estee Lauder discloses data breach via Oracle E-Business flaw BleepingComputer Jun 30, 2026
- Oracle E-Business Suite file transfer flaw under attack NVD/CISA KEV Jun 29, 2026
- Hackers stole Estee Lauder staff's bank and health data. The company took nearly a year to say so. The Next Web Jul 22, 2026
- Hackers now exploit critical Oracle E-Business flaw in attacks BleepingComputer Jun 29, 2026
- Estee Lauder data breach exposes personal info The Cyber Express Jul 15, 2026
- Cybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizations TechCrunch Jun 10, 2026
- PeopleSoft exploit behind 100+ breaches gets patched in Oracle's record July CPU Tech Times Jul 21, 2026
- Google says ShinyHunters hackers targeting education sector via Oracle exploit Reuters Jun 11, 2026 unverified
- Oracle PeopleSoft Zero-Day Exploited in 100+ Breaches Tech Times Jun 16, 2026
- Kodak confirms data breach claimed by ShinyHunters extortion gang BleepingComputer Jun 17, 2026
Related reports
- Shinyhunters ransomware claims RingCentral, Inc. Jul 27, 2026
- ShinyHunters claims attack on Ernst & Young Jul 27, 2026
- EY breach threatens to expose client tax data Jul 27, 2026
- Estée Lauder hack steals customer data Jul 21, 2026
- Ernst & Young Data Breach Affects Personal, Financial Information Jul 20, 2026
- Fortinet FortiSandbox zero-days need urgent patches Jul 17, 2026
- EY data breach via hacked support system Jul 17, 2026
- FortiSandbox bug can let attackers run commands Jul 16, 2026
- Oracle E-Business Suite zero-day under attack Jul 16, 2026
- Microsoft fixes two zero-day flaws in latest patch Jul 16, 2026
- Shinyhunters ransomware claims Abbott owned Exact Sciences Corporation Jul 15, 2026
- Oracle E-Business Suite file transfer flaw under attack Jul 15, 2026