ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
ShinyHunters used an Oracle PeopleSoft zero-day to breach universities, steal data, and extort victims before Oracle’s advisory went public.
Intelligence analysis by GPT-5.4 Mini

Mandiant says ShinyHunters, which it tracks as UNC6240, exploited an unpatched PeopleSoft flaw between May 27 and June 9, with universities hit hardest. The incident exposed stolen data, public leak infrastructure, and Oracle guidance focused on containment until patches are confirmed.
A burglar found a weak door in a school office computer system and used it to sneak in, take files, and leave a note demanding payment. It is like finding a back window to a vault and using it before the owner knows the lock is broken.
Analysis
What happened
Google’s Mandiant says the extortion crew ShinyHunters exploited a previously unpatched Oracle PeopleSoft flaw, tracked as CVE-2026-35273, during activity that ran from May 27 to June 9. Oracle’s advisory arrived on June 10, which means the vulnerability was effectively a zero-day while the campaign was active.
Why the bug matters
The flaw affects PeopleSoft Enterprise PeopleTools and is rated 9.8, which puts it in the critical range. Mandiant says it can be reached over HTTP, requires no login, and needs no user interaction. In practical terms, if the Environment Management Hub is exposed to the internet, the server can be taken over.
How the attackers operated
The article says the attackers left exposed infrastructure online, which helped researchers trace the campaign. Mandiant found a chain of public directories, Python SimpleHTTP servers on sequential IPs, a shared shell history file, disguised MeshCentral agents, and a script for spreading through SSH using hardcoded credentials. The script also dropped a ransom-style marker file into PeopleSoft directories.
The staging data reportedly called back to azurenetfiles.net, a domain that was meant to resemble Azure NetApp Files. The attackers also used compressed archives and outbound SSH to move data toward the ShinyHunters leak site.
Impact and response
Mandiant notified more than 100 organizations that matched vulnerable endpoints. About 68% were in higher education, mostly in the United States. The University of Nottingham is named as one of the first confirmed victims, and Have I Been Pwned says the leaked data includes roughly 455,000 unique email addresses plus names, addresses, phone numbers, passport numbers, and sensitive personal details.
Oracle’s immediate mitigation advice is to disable or remove the Environment Management Hub where possible, or block key endpoints at the perimeter. Mandiant also warns that WAF body-inspection rules alone are not enough. The bigger concern is strategic: ShinyHunters has largely relied on social engineering and stolen access before, and this campaign suggests interest in more direct enterprise software exploitation.
Key points
- Mandiant says ShinyHunters exploited Oracle PeopleSoft CVE-2026-35273 before Oracle’s advisory was published.
- The flaw is critical, can be reached over HTTP, and needs no login or user interaction.
- Universities were hit hardest, with Mandiant saying 68% of notified organizations were in higher education.
- Stolen data from at least one confirmed victim, the University of Nottingham, includes large numbers of personal records.
- Oracle and Mandiant recommend disabling or blocking the Environment Management Hub and checking for signs of compromise.
Oracle and Mandiant have already published mitigation steps, so organizations can shut exposed services, block risky endpoints, and look for signs of compromise. If affected schools and enterprises act quickly, they may stop further theft and prevent the same flaw from spreading to more victims.
If exposed PeopleSoft systems stay online, attackers can keep exploiting them before patching is complete. The article also suggests that some victims were already compromised and had data posted, so delayed response could mean more leaks, more extortion, and more stolen personal information.



