Contained High impact Data breach Checked 1d ago

ShinyHunters breach 100+ orgs via Oracle PeopleSoft flaw

A criminal group known as ShinyHunters exploited a critical unpatched flaw in Oracle PeopleSoft software to break into more than 100 organizations, most of them universities, before Oracle issued an emergency patch. Confirmed victims include the insurance regulator group NAIC and carmaker Nissan, whose current and former employee data was stolen. Oracle's July security update addressed the flaw further, but only a small number of the 100-plus targeted organizations have been publicly confirmed so far.

Started
Aug 9, 2025
Latest activity
Aug 18, 2026
Attributed to
ShinyHuntersLikely
Where
United States, Japan
Sectors
Education, Finance, Manufacturing, Government, Retail, Multiple sectors +2
Scale
more than 100 organizations targeted, about two thirds of them universities, with only a handful publicly confirmed

Current status

After July 29, reporting showed ShinyHunters remained active in separate attacks, but no credible PeopleSoft-specific activity or new confirmed PeopleSoft victims was reported through September 8, 2026.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

Security researchers and multiple outlets, citing Google-owned threat intelligence, linked the campaign to the ShinyHunters extortion group; the group itself has also claimed some of the thefts.

Impact

Attackers stole data from breached organizations before Oracle patched the flaw. Nissan confirmed theft of current and former employee data. NAIC confirmed theft of public financial reports, credit rating data, and some technical files, but did not confirm the attacker's claim of taking 3.1 TB. NAIC said on August 18 that all needed credit rating feeds had returned and related investment ratings were being published again.

What to do

PeopleSoft administrators should confirm Oracle's emergency and July patches are installed and watch for notification letters if they work for or attended an affected organization.

Timeline

  1. Sep 8, 2026

    BleepingComputer reported that ShinyHunters claimed access to a Florida DMV database. Florida officials had not confirmed the breach, and no link to the PeopleSoft campaign was reported.

    Containedbleepingcomputer.com
  2. Sep 7, 2026

    CPO Magazine reported that ShinyHunters claimed a Carhartt breach affecting nearly 13 million people. The report did not link it to the Oracle PeopleSoft campaign.

    Containedcpomagazine.com
  3. Aug 28, 2026

    McKesson disclosed unauthorized access to third-party applications after ShinyHunters claimed patient-data theft. The reporting did not link the incident to the Oracle PeopleSoft campaign.

    Containedbleepingcomputer.com
  4. Aug 18, 2026

    NAIC said it was receiving all needed credit rating feeds and had resumed publishing related investment ratings on August 17.

    Containedcontent.naic.org
  5. Aug 10, 2026

    NAIC said all credit rating provider feeds needed for its filing exempt process had resumed.

    Containedcontent.naic.org
  6. Aug 10, 2026

    NAIC said all credit rating provider data feeds needed for its filing exempt process, which had been paused since the breach, had resumed.

    Containedcontent.naic.org
  7. Aug 4, 2026

    A security outlet reported the Brinks Home breach and an earlier ADT breach were carried out by the same group using a phone call to trick an employee rather than malware, though this specific claim has not been confirmed by either company.

    Activekomando.com
  8. Aug 4, 2026

    Brinks Home refused to pay the ransom, and ShinyHunters leaked roughly 41 gigabytes of the stolen customer data online, including real support conversation records.

    Active
  9. Aug 2, 2026

    Security researchers reported a wave of fake extortion emails signed with the ShinyHunters name, including one using data from the unrelated April 2026 Carnival Corporation breach, demanding $2,000 in Litecoin from people who were never actually breached by the group.

    Activebleepingcomputer.com
  10. Aug 1, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  11. Jul 31, 2026

    Brinks Home confirmed the breach and further coverage described hackers leaking files, with customer contact information and millions of chat logs among the data potentially exposed.

    Activeinc.com
  12. Jul 30, 2026

    Brinks Home Security disclosed it found unauthorized system access on July 20; ShinyHunters claimed to have stolen about 4.9 million Salesforce records and threatened to publish them, while Brinks Home said its alarm monitoring and customer service stayed operational.

    Activebleepingcomputer.com
  13. Jul 29, 2026

    Health-ISAC warned healthcare and medical technology organizations of a rise in successful ShinyHunters data theft attacks.

    Activebleepingcomputer.com
  14. Jul 27, 2026

    Ernst & Young's data breach, disclosed publicly this day, was claimed by ShinyHunters, which said it got credentials for some EY systems through a supply-chain attack and threatened to leak the data if not paid by month's end.

    Activebleepingcomputer.com
  15. Jul 27, 2026

    Coverage of the campaign's scope continued to run, with ShinyHunters still listing new named victims and leaked data.

    Activemartincid.com
  16. Jul 22, 2026

    The Next Web reported that Estee Lauder's disclosure involved a separate August 2025 Oracle E-Business Suite breach linked to Clop, not the 2026 ShinyHunters PeopleSoft campaign.

    Containedthenextweb.com
  17. Jul 21, 2026

    Oracle's July Critical Patch Update fixed the PeopleSoft flaw chain that ShinyHunters used to breach roughly 300 servers across 100-plus organizations.

    Containedtechtimes.com
  18. Jul 21, 2026

    Oracle's July critical patch update closed the exploited flaw, and Estee Lauder disclosed that customer and employee data was taken from its Oracle E-Business Suite HR system.

    Containedsecurityweek.com
  19. Jul 21, 2026

    Oracle closed the PeopleSoft/E-Business Suite flaw chain in a record-sized July Critical Patch Update, and Estee Lauder confirmed attackers had taken personal, financial, and health data dating back to an August 2025 intrusion.

    Containedsecurityweek.com
  20. Jul 21, 2026

    Oracle's July Critical Patch Update closed the exploited PeopleSoft/EBS flaw chain, and Estee Lauder detailed the personal, financial, and health data taken from its systems.

    Containedsecurityweek.com
  21. Jul 21, 2026

    Estee Lauder disclosed a data breach tied to the Oracle E-Business Suite flaw, and Oracle released its July Critical Patch Update closing the exploited flaws.

    Containedtechtimes.com
  22. Jul 21, 2026

    Oracle's July Critical Patch Update further addressed the PeopleSoft exploit chain used in the breaches.

    Containedtechtimes.com
  23. Jul 16, 2026

    CISA ordered US federal agencies to patch the actively exploited Oracle E-Business Suite flaw by that Saturday.

    Activebleepingcomputer.com
  24. Jul 16, 2026

    CISA ordered US federal agencies to patch the actively exploited Oracle EBS flaw by that Saturday.

    Activebleepingcomputer.com
  25. Jul 16, 2026

    CISA added the Oracle E-Business Suite flaw to its known exploited vulnerabilities list and ordered federal agencies to patch within days.

    Activebleepingcomputer.com
  26. Jun 30, 2026

    Nissan disclosed that current and former employee data was stolen via the same campaign.

    Activesecurityweek.com
  27. Jun 30, 2026

    Nissan and Estee Lauder disclosed employee and HR data theft tied to the same Oracle PeopleSoft campaign, with reporting noting only a handful of the 100-plus targeted organizations confirmed so far.

    Activesecurityweek.com
  28. Jun 30, 2026

    Nissan and Estee Lauder disclosed employee and customer data theft tied to the same Oracle flaw campaign.

    Activebleepingcomputer.com
  29. Jun 30, 2026

    SecurityWeek reported that only a handful of the roughly 100 organizations ShinyHunters claims to have hit had been publicly confirmed.

    Activesecurityweek.com
  30. Jun 30, 2026

    SecurityWeek reported only a handful of the roughly 100 targeted organizations had been publicly confirmed.

    Activesecurityweek.com
  31. Jun 29, 2026

    NAIC said the stolen data from its breach was limited to public information, outdated logs, and configuration files.

    Activebleepingcomputer.com
  32. Jun 29, 2026

    The NAIC, the US insurance regulators' association, confirmed its systems were breached through the same Oracle flaw.

    Activeinfosecurity-magazine.com
  33. Jun 29, 2026

    NAIC confirmed attackers exploited an Oracle PeopleSoft zero-day and the ShinyHunters group claimed to have stolen 3.1 TB of data.

    Emergingsecurityweek.com
  34. Jun 29, 2026

    NAIC confirmed attackers used a PeopleSoft zero-day to access its systems; CISA added the related Oracle EBS flaw CVE-2026-46817 to its Known Exploited Vulnerabilities catalog the same day.

    Activeinfosecurity-magazine.com
  35. Jun 29, 2026

    The National Association of Insurance Commissioners confirmed a breach, with ShinyHunters claiming 3.1 TB of stolen data.

    Activesecurityweek.com
  36. Jun 29, 2026

    The insurance regulators group NAIC confirmed a breach, with ShinyHunters claiming 3.1 TB of stolen data; separately, attackers began exploiting a new Oracle E-Business Suite flaw.

    Activesecurityweek.com
  37. Jun 29, 2026

    NAIC confirmed ShinyHunters stole an estimated 3.1 TB of data from its systems.

    Activesecurityweek.com
  38. Jun 17, 2026

    Kodak confirmed a data breach after ShinyHunters claimed to have stolen 2.2 million records.

    Activebleepingcomputer.com
  39. Jun 17, 2026

    Nissan disclosed that current and former employee data was stolen in an attack linked to the PeopleSoft campaign.

    Activebleepingcomputer.com
  40. Jun 17, 2026

    Nissan disclosed a data breach of current and former employee data linked to the Oracle PeopleSoft attacks.

    Activebleepingcomputer.com
  41. Jun 17, 2026

    Nissan disclosed that current and former employee data was stolen in the campaign.

    Activebleepingcomputer.com
  42. Jun 16, 2026

    Reports put the flaw, CVE-2026-35273 with a 9.8 severity score, behind more than 100 breaches with no patch yet available.

    Activetechtimes.com
  43. Jun 12, 2026

    Oracle issued an out-of-band emergency patch for the PeopleSoft PeopleTools flaw.

    Activecomputerweekly.com
  44. Jun 11, 2026

    Google's Mandiant and Threat Intelligence Group said ShinyHunters was actively exploiting an Oracle PeopleSoft flaw to breach organizations, mostly universities.

    Emergingreuters.com
  45. Jun 11, 2026

    Oracle confirmed and issued mitigation guidance for the critical PeopleSoft flaw, tracked as CVE-2026-35273, that was being actively exploited.

    Activebleepingcomputer.com
  46. Jun 11, 2026

    Oracle issued an out of band fix for the PeopleSoft zero day, tracked as CVE-2026-35273, after confirming active exploitation.

    Activebleepingcomputer.com
  47. Jun 11, 2026

    Researchers said ShinyHunters had exploited CVE-2026-35273 to breach over 100 organizations, mostly universities.

    Activethenextweb.com
  48. Jun 10, 2026

    ShinyHunters told TechCrunch it had breached Oracle PeopleSoft servers at more than 100 organizations, mostly universities.

    Emergingtechcrunch.com
  49. Jun 10, 2026

    BleepingComputer reported ShinyHunters actively stealing data from Oracle PeopleSoft servers, claiming over 100 organizations hit.

    Emergingbleepingcomputer.com
  50. Jun 10, 2026

    ShinyHunters began claiming theft of data from Oracle PeopleSoft servers at more than 100 organizations.

    Emergingbleepingcomputer.com
  51. Jun 10, 2026

    BleepingComputer reported that ShinyHunters was exploiting an Oracle PeopleSoft zero-day to steal data from over 100 organizations.

    Emergingbleepingcomputer.com
  52. May 31, 2026

    Reports emerged that a zero-day flaw in Oracle PeopleSoft was being exploited in a widespread attack.

    Emergingyahoo.com

Sources

Related reports