Story
ShinyHunters Hackers Renew Attacks on Oracle PeopleSoft Flaw, Google's Mandiant Reports

Summary
Google's cybersecurity unit, Mandiant, reports that the hacking group ShinyHunters has resumed and adapted its exploitation of a known vulnerability in Oracle's PeopleSoft enterprise software, targeting organizations that failed to apply a full security patch.
The hacking group ShinyHunters has renewed a “mass exploitation” campaign targeting a security flaw in Oracle’s PeopleSoft enterprise software, according to a threat intelligence report released Friday by Google’s cybersecurity unit, Mandiant.
Evolving Attack Methods
Mandiant stated that the hackers have adapted their tactics following an initial wave of attacks between May 27 and June 9, which primarily affected universities. The group is now targeting organizations that implemented defensive web application firewall (WAF) rules but did not apply the official software update Oracle issued to patch the vulnerability.
This evolution in strategy highlights a significant risk for institutions relying on partial mitigation measures instead of comprehensive patching. According to Mandiant, the latest attacks have impacted dozens of systems globally across a wide range of sectors, including:
- Higher education
- Technology
- Healthcare
- Agriculture
- Transportation
- Government
Connection to High-Profile Breaches
AdThe report comes just days after ShinyHunters claimed responsibility for a major data breach at the U.S. Federal Bureau of Investigation (FBI), allegedly accessing personnel data by exploiting a vulnerability in PeopleSoft. The FBI confirmed in a statement on Wednesday that it was "aggressively investigating" the reported breach.
Reuters, which first reported on the FBI breach claim, has not been able to independently corroborate that the PeopleSoft flaw was the entry point. The renewed attacks are likely to heighten concerns for the many organizations that use the popular Oracle software for human resources and other critical business functions.
Market and Security Implications
The ongoing exploitation of a known and patched vulnerability underscores the critical importance of timely software updates for corporate and government entities. Relying on intermediary defenses like firewalls can provide a false sense of security, as sophisticated actors can often find ways to circumvent them.
Oracle (NYSE: ORCL) did not respond to requests for comment on the matter, according to Reuters. The situation serves as a stark reminder to investors and IT security professionals of the persistent and adaptive nature of cyber threats targeting widely used enterprise software.
Read next
More on Stocks
European Telecoms Face AI-Driven Price Pressure, Bank of America Warns
Bank of America analysts report that while AI agents could increase customer churn for European telecom operators by simplifying price comparisons, the technology also offers powerful tools for sales and personalized customer retention.

Manulife Stock Climbs, Supported by Cross-Border Investor Optimism
Shares of Manulife Financial gained on Tuesday, buoyed by a strong performance in U.S. markets rather than any specific company news. The stock's move is also supported by a bullish technical posture and positive analyst ratings.

Escondida Union Rejects BHP's Bid to Pause Talks After Fatal Accident
A union at the world's largest copper mine, Escondida, has rejected a request from operator BHP to postpone contract negotiations following a fatal accident earlier this week. The union accused the company of using the tragedy to delay the collective bargaining process.

Oura IPO Heavily Oversubscribed, Targeting Up to $2.2 Billion
Smart ring maker Oura Inc. has received orders for roughly four times the number of shares available in its initial public offering, which aims to raise as much as $2.2 billion, according to a report.