Google Threat Intelligence Group confirmed the ShinyHunters extortion group exploited a critical unpatched zero day (CVE 2026 35273, CVSS 9.8) in Oracle PeopleSoft to compromise roughly 300 instances across more than... 68% of the victims were in the higher education sector; the University of Nottingham was the firs...

Create a landscape editorial hero image for this Studio Global article: What did Google confirm about the ShinyHunters hacking group's exploitation of an Oracle PeopleSoft zero-day vulnerability, including detail. Article summary: Here is what Google's Mandiant and Threat Intelligence Group (GTIG) confirmed about the ShinyHunters campaign targeting Oracle PeopleSoft:. Topic tags: general, general web. Reference image context from search candidates: Reference image 1: visual subject "# Google Confirms Data Breach Linked to ShinyHunters. ## In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon. Google has confirmed that in" source context "Google Confirms Data Breach Linked to ShinyHunters" Reference image 2: visual subject "# Google Confirms Data Breach Linked to ShinyHunters. ## In this blog series we spotlight one of the stories from our cybersecu
In a coordinated disclosure, Google's Mandiant and Threat Intelligence Group (GTIG) have confirmed a two-week-long exploitation campaign by the financially motivated extortion group ShinyHunters (tracked as UNC6240) that leveraged a critical zero-day vulnerability in Oracle PeopleSoft. The flaw allowed attackers to remotely execute code on vulnerable servers without any authentication, leading to data theft across predominantly educational institutions. The activity occurred before Oracle published its out-of-band security alert, leaving organizations without an official patch during the active intrusion window.
The vulnerability, assigned CVE-2026-35273, resides in the Environment Management component of Oracle PeopleSoft PeopleTools and carries a maximum severity CVSS score of 9.8 . It allows unauthenticated remote code execution (RCE) over HTTP/HTTPS, meaning an attacker needs no login credentials or user interaction—only network access to the targeted server
.
The specific attack vector targeted Environment Management Hub (PSEMHUB) endpoints. Google observed malicious POST requests to paths such as /PSEMHUB/hub and /PSIGW/HttpListeningConnector . The vulnerability affects PeopleTools versions 8.61 and 8.62
. Critically, the campaign's timeline from May 27 to June 9, 2026, entirely predates Oracle's June 10 advisory, confirming the bug was exploited in the wild as an unpatched zero-day
.
Google's investigation revealed a broad and focused operation. ShinyHunters compromised approximately 300 distinct PeopleSoft instances spread across more than 100 organizations globally . GTIG took the proactive step of notifying over 100 of these exposed organizations during the active exploitation window
.
The campaign displayed a clear pattern of targeting. 68% of the known victims were entities within the higher education sector, primarily colleges and universities, with the majority based in the United States .
To maintain persistence and control, the attackers deployed MeshCentral remote management agents, but disguised the filenames as legitimate Microsoft Azure services, using names such as meshagent64-azure-ops.exe. The command-and-control infrastructure further mimicked Azure by using the domain azurenetfiles.net . The stolen data was later published on the ShinyHunters Data Leak Site (DLS) on June 9, 2026
.
The University of Nottingham became the first publicly confirmed victim, providing a stark illustration of the breach's consequences. The university acknowledged a cyber incident affecting its student records system, confirming that a significant amount of data, totaling tens of gigabytes, had been accessed .
Reports from multiple sources indicate that between 454,600 and 500,000 personal and academic records belonging to current and former students were stolen . The compromised data primarily consisted of student and alumni records, but the university noted that staff bank details and research data were not part of the breach
. The stolen data, which included details like home addresses, phone numbers, and dates of birth, was quickly published on ShinyHunters' leak site and indexed by “Have I Been Pwned”
.
While Oracle issued an out-of-band security alert on June 10, 2026, the initial guidance consisted of workarounds rather than a complete software fix. Google’s threat intelligence blog, in alignment with Oracle’s advisory, recommends organizations take the following immediate steps to protect vulnerable PeopleSoft instances :
/PSEMHUB/* and /PSIGW/HttpListeningConnector, using network firewalls or access control lists /PSEMHUB/hub and /PSIGW/HttpListeningConnector originating from external IP addresses to identify historical compromise .jsp files that an attacker may have planted, particularly under the path /webserv/applications/peoplesoft/PSEMHUB.war/ logs, persistantstorage, or scratchpad within PSEMHUB paths. Additionally, scrutinize any outbound SMB traffic from PeopleSoft servers, which could indicate data exfiltration These steps are critical stopgap measures. Organizations running PeopleTools versions 8.61 and 8.62 must prioritize applying Oracle's official out-of-band security update when it becomes available to fully remediate the risk of further exploitation .
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Google Threat Intelligence Group confirmed the ShinyHunters extortion group exploited a critical unpatched zero day (CVE 2026 35273, CVSS 9.8) in Oracle PeopleSoft to compromise roughly 300 instances across more than...
Google Threat Intelligence Group confirmed the ShinyHunters extortion group exploited a critical unpatched zero day (CVE 2026 35273, CVSS 9.8) in Oracle PeopleSoft to compromise roughly 300 instances across more than... 68% of the victims were in the higher education sector; the University of Nottingham was the first confirmed public victim, with up to 500,000 student records stolen.
Immediate workarounds include disabling or removing the PSEMHUB application, blocking external access to specific endpoints, and auditing logs for signs of compromise.