Jul 26, 2026 · 2:11 AM
Subscribe
Home Business

A single Oracle PeopleSoft bug gave ShinyHunters two weeks to ransack 100 universities before anyone noticed

A 9.8-severity zero-day in Oracle PeopleSoft gave the ShinyHunters extortion group an uncontested two-week window to breach 300-plus servers across 100 organizations, mostly universities, before Oracle issued an advisory. Moody Bible Institute alone had 2.3 million records exposed. Oracle's permanent fix arrived in its July 2026 Critical Patch Update.

Judith Murphy
· 5 min read · 573 reads
A single Oracle PeopleSoft bug gave ShinyHunters two weeks to ransack 100 universities before anyone noticed

ShinyHunters used a critical Oracle PeopleSoft flaw before customers had a public warning, and universities took the hardest hit. If you still run exposed legacy ERP systems, this is the part you can't ignore.

The Oracle PeopleSoft bug was not a theoretical risk sitting in a patch note. Google Cloud's Mandiant team said ShinyHunters, tracked by Google as UNC6240, exploited CVE-2026-35273 between May 27 and June 9, 2026, before Oracle published its June 10 security alert. That's the ugly part.

The vulnerability sits in the Environment Management component of PeopleSoft Enterprise PeopleTools and carries a CVSS score of 9.8. Oracle's own alert describes it as remotely exploitable without authentication. No login. No user click. Just network access to the exposed service. For an ERP system holding student, HR, payroll, finance, and campus data, that's about as bad as it gets.

Mandiant said it notified more than 100 organisations. Of those, 68% were in higher education. ShinyHunters claimed it targeted roughly 300 PeopleSoft instances across about 100 organisations, according to SecurityWeek and CyberScoop. That distinction matters: Google confirmed exposure and compromise activity, while the bigger victim count remains partly based on the criminals' own claims. Don't blur the two.

The attack path was blunt. Mandiant said the group targeted PeopleSoft Environment Management Hub endpoints, including PSEMHUB, and used attacker staging systems with customized MeshCentral agents. It also found signs of administrative command queries and a custom lateral movement and defacement script. This wasn't magic. It was reconnaissance, exposed infrastructure, and a critical bug that arrived before defenders had a public advisory to point at.

The universities were carrying the data

Moody Bible Institute is one of the clearest examples so far. TechTimes reported that ShinyHunters claimed to have stolen about 23GB of data from the Chicago institution, including roughly 46 million communication records, about 2.2 million enrollment lead records, more than 108,000 biographical master files, donor gift data, employee payroll XML files, admissions outreach files, and student housing assignment records. Have I Been Pwned put the number of unique email addresses in the Moody dataset at about 2.3 million.

Keep the caveat in view. Moody said in a June 22 statement that it was still working to understand the nature of the compromised data, according to TechTimes. Threat actor spreadsheets are not audited breach notices. Still, when a school is on a leak site and the data is indexed by Have I Been Pwned, you don't treat it as rumor.

The University of Nottingham was hit too. SecurityWeek called it the first confirmed victim tied to the PeopleSoft campaign, and Have I Been Pwned later listed 454,600 affected Nottingham accounts. Reporting from Recorded Future News, ITV News, and others said the university took affected systems offline, launched a forensic investigation, and reported the incident to Action Fraud and the UK Information Commissioner's Office. The exposed fields reportedly included names, addresses, phone numbers, dates of birth, passport numbers, academic enrolment details, fee payment information, ethnicities, disabilities, and email addresses.

That is not a narrow email breach. It is a student-records breach, and there is a difference. You can reset a password. You can't quickly reset a birth date, a home address history, or a passport number that has already been copied into a criminal marketplace.

This is a legacy systems story

The easy line is to blame universities for slow patching. Some of that is fair. Many colleges run old administrative stacks, stretched IT teams, and procurement cycles that move more slowly than attackers do. But the vendor timeline matters as well. Oracle published an out-of-band security alert on June 10 after exploitation had already been observed, and the company's public CVE mapping still ties CVE-2026-35273 to that security alert rather than to the July Critical Patch Update.

So the earlier claim that a permanent fix arrived inside Oracle's July 2026 Critical Patch Update is too strong. Oracle's July CPU was real, and InfoWorld reported it was the company's largest ever, with 1,449 new patches across 32 product families. But CVE-2026-35273 belongs to the June security alert. CyberScoop also reported on June 12 that Oracle had not released a patch at that point and had instead provided mitigation steps. That is the fact pattern you can stand behind.

There's a broader warning here for founders and CISOs selling into enterprise IT. The billions now going into AI infrastructure have not made PeopleSoft, WebLogic, legacy HR suites, and campus systems disappear. They still sit in the middle of organisations, full of useful data and often reachable through configurations nobody wants to own. ShinyHunters didn't need a nation-state technique. It needed a scanner, exposed PeopleSoft endpoints, and time.

The education sector had already been shaken this spring by the Instructure Canvas breach. Inside Higher Ed reported in May that Instructure reached a ransom deal after hackers claimed access to data tied to about 275 million users across more than 8,800 institutions. That incident involved a different platform and a different weakness, but the lesson for schools is painfully similar: vendors hold the systems, attackers hold the timetable, and students are the ones who live with the leaked data.

Frankly, any institution still treating ERP exposure as back-office risk is behind the story. These systems are not back office when they hold donor records, payroll data, passport fields, academic histories, and years of applicant information. They are the prize.

Also read: Guillermo Rauch says AI agents now trigger more than half of all Vercel deploymentsCorgi tripled its valuation to $4 billion in eight weeks and is using the money to open coffee shopsThe Trump Trade has lost 16% since May and the Iran conflict just exposed its fatal flaw

TOPICS
Judith Murphy is a financial journalist and market analyst covering AI, technology stocks, and emerging market trends. She has contributed to multiple financial publications and brings a data-driven approach to her coverage of the technology sector and its impact on global markets.
Related Articles
More posts →
Loading next article…
You're all caught up