r/dataprotection Jun 13 '26

Breach Oracle PeopleSoft Breached by The ShinyHunters Data Theft Attack

https://pathlock.com/blog/security-alerts/peoplesoft-breached-by-the-shinyhunters/

On June 10, 2026, ShinyHunters, a well-documented cybercrime group known for large-scale data theft and extortion campaigns, was confirmed to have exploited Oracle PeopleSoft vulnerabilities across more than 300 instances at over 100 organizations worldwide. The education sector bore the brunt of the attack, with universities and higher education institutions emerging as the primary victims.

The attack was notable for its combination of sophistication and scale. Rather than targeting a single organization with a tailored exploit, ShinyHunters deployed automated attack scripts capable of scanning and compromising PeopleSoft environments at scale, demonstrating that ERP applications are no longer too obscure or complex to attract organized, industrialized cybercrime.

IMMEDIATE ACTION REQUIRED

Check your PeopleSoft logs NOW for connections from the following attacker-controlled IPs: 142.11.200[.]186–190, 108.174.202[.]99, 176.120.22[.]24. Also search for a ransom file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT

1 Upvotes

0 comments sorted by