Find notable cyber news and cases, enriched with sources, timelines, and signals.

ShinyHunters Oracle PeopleSoft data theft and extortion campaign

Campaign
First reported
Last updated
Happening score
H score 60
3 unique sources, 4 articles

Summary

Hide ▲

ShinyHunters/UNC6240 used CVE-2026-35273 in Oracle PeopleSoft Enterprise PeopleTools as a zero-day to break into exposed systems, steal data, and extort victims between May 27 and June 9. Mandiant says the campaign affected more than 100 organizations, with universities hit heavily and University of Nottingham among the confirmed victims after about 455,000 email addresses were leaked. New reporting adds Nissan as a victim: the company says attackers targeted its Oracle PeopleSoft environment and may have exposed employee information for current and former staff in the United States, Canada, Mexico, and Brazil.

Related Happenings

Nissan employee data leak via Oracle PeopleSoft zero-day

Data Leak
H score49 First: 30.06.2026 19:00 Last: 30.06.2026 19:00 Sources 1

How related: Nissan has disclosed that current and former employees may have had sensitive personal data stolen, including Social Security numbers, banking details and tax records, after attackers exploited a zero-day flaw in Oracle's PeopleSoft software.

About this happening: Nissan disclosed a data leak affecting current and former employees after attackers exploited Oracle PeopleSoft, exposing sensitive payroll and identity records ac...

Nissan hit by network compromise

Incident
H score48 First: 29.06.2026 23:40 Last: 29.06.2026 23:40 Sources 1

How related: Nissan has disclosed that current and former employees may have had sensitive personal data stolen, including Social Security numbers, banking details and tax records, after attackers exploited a zero-day flaw in Oracle's PeopleSoft software.

About this happening: Nissan disclosed a data breach affecting current and former employees after unauthorized access tied to Oracle PeopleSoft exploitation put personnel records at ris...

Oracle PeopleSoft broad zero-day exploitation campaign

Exploitation Wave
H score82 First: 29.06.2026 13:00 Last: 29.06.2026 13:00 Sources 1

About this happening: A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...

Infinite Campus hit by data theft breach linked to ShinyHunters

Incident
H score51 First: 15.06.2026 15:38 Last: 15.06.2026 15:38 Sources 1

About this happening: Infinite Campus suffered a Salesforce data theft breach that exposed more than 137,000 school staff accounts, putting staff contact and account data at risk. The compr...

Council of Europe ShinyHunters data leak claim

Data Leak
H score82 First: 15.06.2026 13:44 Last: 15.06.2026 13:44 Sources 1

About this happening: ShinyHunters has posted the Council of Europe on a Tor-based leak site, claiming a data theft that could expose more than 297 GB and over 429,000 files. The al...

Timeline

  1. 29.06.2026 23:40 2 articles · 16d ago

    Nissan discloses employee data breach tied to Oracle PeopleSoft attacks

    Victim Impact Update

    Nissan says attackers exploited an Oracle PeopleSoft vulnerability in a ShinyHunters-linked campaign and that the company was specifically targeted, with personal information for current and former employees in the United States, Canada, Mexico, and Brazil potentially exposed. Nissan says the material may include employee contact information, banking information, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary information, and the company has activated incident response, engaged external cybersecurity experts, secured affected systems, and is working with Oracle.

    Show sources
  2. 11.06.2026 23:29 1 articles · 1mo ago

    ShinyHunters exploits Oracle PeopleSoft zero-day

    Exploitation Observed

    Google's Mandiant says the UNC6240 cluster used CVE-2026-35273, a PeopleSoft Enterprise PeopleTools zero-day, to break into Oracle PeopleSoft systems and steal data between May 27 and June 9. Oracle did not publish its advisory until June 10, so the flaw remained unpatched throughout the activity window.

    Show sources
  3. 10.06.2026 21:31 2 articles · 1mo ago

    Oracle PeopleSoft customers receive ShinyHunters extortion demands

    Initial Disclosure

    Oracle PeopleSoft cloud and on-premises customer instances were identified as targets of widespread data theft attacks, and affected customers were receiving extortion demands signed by the ShinyHunters extortion gang.

    Show sources
  4. 10.06.2026 21:31 1 articles · 1mo ago

    ShinyHunters claims data theft from 300 Oracle PeopleSoft instances

    Attribution Update

    ShinyHunters confirmed it was behind the Oracle PeopleSoft attacks and claimed stolen data from 300 instances across more than 100 organizations, saying the operation used a gadget chain of old and zero-day vulnerabilities and that success varied by instance configuration.

    Show sources