Cybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizations
ShinyHunters claims it breached Oracle PeopleSoft servers at more than 100 organizations, many of them universities. The group says it exfiltrated sensitive records.
Intelligence analysis by GPT-5.4 Mini

A member of the notorious ShinyHunters group told TechCrunch it had compromised Oracle PeopleSoft servers at over 100 organizations, with universities among the main targets. The claim follows earlier reporting by BleepingComputer and includes allegations of stolen student and administrative data.
A hacker gang says it broke into a kind of school-and-work computer system used by many groups at once, like one master key opening lots of lockers. If true, it could have exposed private student details and other records.
Analysis
What happened
A member of the cybercrime group ShinyHunters told TechCrunch that the group had hacked Oracle PeopleSoft servers at more than 100 organizations. The story says many of the victims were universities, and that the breaches were first reported by BleepingComputer.
What was allegedly taken
According to the hacker message quoted in the article, the stolen data included "student, applicant, financial aid, immigration, health, and administrative data." The group also claimed to have taken student records containing home addresses, phone numbers, email addresses, and dates of birth.
The group’s approach
TechCrunch says this fits ShinyHunters’ pattern of finding vulnerabilities in widely used software so it can hit many victims at once. The article describes mass hacking as the group’s specialty and says the group has remained active and visible in recent months.
Another stated target
The member said the group’s original aim was to compromise an FBI PeopleSoft server, apparently to post a denial that ShinyHunters was behind a wave of swatting attempts the FBI warned about in an alert last month. The member said that effort failed.
Oracle did not respond to TechCrunch’s request for comment, so the article does not include confirmation from Oracle or the affected organizations. The report is therefore based on a criminal claim, not a verified forensic disclosure.
Key points
- ShinyHunters claimed it breached Oracle PeopleSoft servers at more than 100 organizations.
- Many of the alleged victims were universities, according to the report.
- The hackers claimed to have exfiltrated student and administrative data, including addresses and phone numbers.
- The group said it originally tried to compromise an FBI PeopleSoft server, but failed.
- Oracle did not respond to TechCrunch’s request for comment.
If organizations quickly confirm the affected systems, they can isolate them, stop further access, and reset credentials before more data leaves the network. The publicity could also push institutions to patch PeopleSoft systems and review old security gaps more aggressively.
If the claim is accurate, the breach could expose sensitive personal and administrative data across many organizations, especially universities. Because the group says it targeted a common software platform, the incident could also signal more attacks on other PeopleSoft customers.



