Oracle warns customers of critical PeopleSoft attacks after hundreds of servers hacked by apparent ShinyHunter data theft attack


  • ShinyHunters is likely behind the CVE-2026-35273 attack on Oracle’s PeopleSoft
  • Versions 8.61 and 8.62 are affected, users are encouraged to take “immediate action”
  • Google’s Mandiant informed over 100 organizations

Oracle PeopleSoft servers used by universities, businesses and public sector organizations are being targeted in a new attack by the ShinyHunters extortion group, researchers have revealed.

The attackers claim to have compromised more than 100 organizations and exfiltrated data from about 300 PeopleSoft instances by exploiting a vulnerability tracked as CVE-2026-35273.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top