ShinyHunters used a critical Oracle PeopleSoft flaw before customers had a public warning, and universities took the hardest hit. If you still run exposed legacy ERP systems, this is the part you can't ignore.
The Oracle PeopleSoft bug was not a theoretical risk sitting in a patch note. Google Cloud's Mandiant team said ShinyHunters, tracked by Google as UNC6240, exploited CVE-2026-35273 between May 27 and June 9, 2026, before Oracle published its June 10 security alert. That's the ugly part.
The vulnerability sits in the Environment Management component of PeopleSoft Enterprise PeopleTools and carries a CVSS score of 9.8. Oracle's own alert describes it as remotely exploitable without authentication. No login. No user click. Just network access to the exposed service. For an ERP system holding student, HR, payroll, finance, and campus data, that's about as bad as it gets.
Mandiant said it notified more than 100 organisations. Of those, 68% were in higher education. ShinyHunters claimed it targeted roughly 300 PeopleSoft instances across about 100 organisations, according to SecurityWeek and CyberScoop. That distinction matters: Google confirmed exposure and compromise activity, while the bigger victim count remains partly based on the criminals' own claims. Don't blur the two.
The attack path was blunt. Mandiant said the group targeted PeopleSoft Environment Management Hub endpoints, including PSEMHUB, and used attacker staging systems with customized MeshCentral agents. It also found signs of administrative command queries and a custom lateral movement and defacement script. This wasn't magic. It was reconnaissance, exposed infrastructure, and a critical bug that arrived before defenders had a public advisory to point at.
The universities were carrying the data
Moody Bible Institute is one of the clearest examples so far. TechTimes reported that ShinyHunters claimed to have stolen about 23GB of data from the Chicago institution, including roughly 46 million communication records, about 2.2 million enrollment lead records, more than 108,000 biographical master files, donor gift data, employee payroll XML files, admissions outreach files, and student housing assignment records. Have I Been Pwned put the number of unique email addresses in the Moody dataset at about 2.3 million.
Keep the caveat in view. Moody said in a June 22 statement that it was still working to understand the nature of the compromised data, according to TechTimes. Threat actor spreadsheets are not audited breach notices. Still, when a school is on a leak site and the data is indexed by Have I Been Pwned, you don't treat it as rumor.
The University of Nottingham was hit too. SecurityWeek called it the first confirmed victim tied to the PeopleSoft campaign, and Have I Been Pwned later listed 454,600 affected Nottingham accounts. Reporting from Recorded Future News, ITV News, and others said the university took affected systems offline, launched a forensic investigation, and reported the incident to Action Fraud and the UK Information Commissioner's Office. The exposed fields reportedly included names, addresses, phone numbers, dates of birth, passport numbers, academic enrolment details, fee payment information, ethnicities, disabilities, and email addresses.
That is not a narrow email breach. It is a student-records breach, and there is a difference. You can reset a password. You can't quickly reset a birth date, a home address history, or a passport number that has already been copied into a criminal marketplace.
This is a legacy systems story
The easy line is to blame universities for slow patching. Some of that is fair. Many colleges run old administrative stacks, stretched IT teams, and procurement cycles that move more slowly than attackers do. But the vendor timeline matters as well. Oracle published an out-of-band security alert on June 10 after exploitation had already been observed, and the company's public CVE mapping still ties CVE-2026-35273 to that security alert rather than to the July Critical Patch Update.
So the earlier claim that a permanent fix arrived inside Oracle's July 2026 Critical Patch Update is too strong. Oracle's July CPU was real, and InfoWorld reported it was the company's largest ever, with 1,449 new patches across 32 product families. But CVE-2026-35273 belongs to the June security alert. CyberScoop also reported on June 12 that Oracle had not released a patch at that point and had instead provided mitigation steps. That is the fact pattern you can stand behind.
There's a broader warning here for founders and CISOs selling into enterprise IT. The billions now going into AI infrastructure have not made PeopleSoft, WebLogic, legacy HR suites, and campus systems disappear. They still sit in the middle of organisations, full of useful data and often reachable through configurations nobody wants to own. ShinyHunters didn't need a nation-state technique. It needed a scanner, exposed PeopleSoft endpoints, and time.
The education sector had already been shaken this spring by the Instructure Canvas breach. Inside Higher Ed reported in May that Instructure reached a ransom deal after hackers claimed access to data tied to about 275 million users across more than 8,800 institutions. That incident involved a different platform and a different weakness, but the lesson for schools is painfully similar: vendors hold the systems, attackers hold the timetable, and students are the ones who live with the leaked data.
Frankly, any institution still treating ERP exposure as back-office risk is behind the story. These systems are not back office when they hold donor records, payroll data, passport fields, academic histories, and years of applicant information. They are the prize.
Also read: Guillermo Rauch says AI agents now trigger more than half of all Vercel deployments • Corgi tripled its valuation to $4 billion in eight weeks and is using the money to open coffee shops • The Trump Trade has lost 16% since May and the Iran conflict just exposed its fatal flaw