Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
ShinyHunters says it stole data from 300 PeopleSoft instances at more than 100 organizations, mostly in education. Oracle had not publicly commented at the time of publication.
Intelligence analysis by GPT-5.4 Mini

ShinyHunters is targeting Oracle PeopleSoft customers in ongoing data theft attacks, hitting both cloud and on-premises deployments. The group says it has stolen data from 300 instances and is using a mix of old and zero-day flaws, while researchers found exposed tooling and indicators tied to the campaign.
A hacker group says it broke into many school and company computer systems that run Oracle PeopleSoft, which stores important records like payroll and student data. Think of it like someone trying many keys on a big filing cabinet, then leaving a threatening note after opening it.
Analysis
What happened
BleepingComputer reports that Oracle PeopleSoft customers are being hit by ongoing data theft attacks attributed to the ShinyHunters extortion gang. The attackers claim they have stolen data from 300 instances across more than 100 organizations, and said many of the victims are in education.
How the campaign works
According to the threat actor, the attacks rely on a “gadget chain” that combines old and zero-day vulnerabilities. They also said the success of the attack may depend on how a PeopleSoft instance is configured, which explains why the campaign does not appear to work everywhere.
The group told the publication that one of its early goals was to breach an FBI PeopleSoft portal, but that attempt failed. The same article says Nottingham University is among the victims and that the university acknowledged a cybersecurity incident.
Evidence and response
Security researcher Michael R found exposed directories linked to the campaign, including staging material, MeshCentral agents, and scripts used for defacement and credential spraying. The exposed files also included a shell script that creates a ransom note named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT after a breach.
The script reportedly looks for PeopleSoft-related systems in /etc/hosts, tries SSH access using common administrative accounts such as psoft, oracle, and linuxadm, and falls back to SSH keys if passwords fail. The article also lists several IP addresses tied to the activity and notes that some used a TLS certificate with the common name azurenetfiles.net, which had previously been linked to ShinyHunters.
Oracle had not responded publicly at publication time. The practical advice from the article is straightforward: check logs for the listed IPs, investigate any signs of access, and isolate affected servers from the internet until the environment is reviewed and secured.
Key points
- ShinyHunters claims it stole data from 300 Oracle PeopleSoft instances at more than 100 organizations.
- The campaign appears to target both cloud and on-premises PeopleSoft environments.
- Researchers found exposed directories, scripts, and IP addresses tied to the attacks.
- The article says many victims are in education, and Nottingham University acknowledged a cybersecurity incident.
- Oracle had not publicly responded at the time of publication.
If organizations spot the listed signs early, they can cut off access, preserve evidence, and limit how much data is taken. The exposed scripts and IPs also give defenders concrete clues to hunt for, which can speed containment across affected PeopleSoft environments.
If the attackers already have valid access or a working exploit path, more organizations could be breached before they notice. Because the campaign appears to target both cloud and on-premises systems, a single misconfigured instance could still leave sensitive data exposed even after partial remediation.



