ShinyHunters Oracle PeopleSoft data theft and extortion campaign
Campaign
Summary
Hide ▲
Show ▼
ShinyHunters/UNC6240 used CVE-2026-35273 in Oracle PeopleSoft Enterprise PeopleTools as a zero-day to break into exposed systems, steal data, and extort victims between May 27 and June 9. Mandiant says the campaign affected more than 100 organizations, with universities hit heavily and University of Nottingham among the confirmed victims after about 455,000 email addresses were leaked. New reporting adds Nissan as a victim: the company says attackers targeted its Oracle PeopleSoft environment and may have exposed employee information for current and former staff in the United States, Canada, Mexico, and Brazil.
Related Happenings
Nissan employee data leak via Oracle PeopleSoft zero-day
Data Leak
H score49
First: 30.06.2026 19:00
Last: 30.06.2026 19:00
Sources 1
How related:
Nissan has disclosed that current and former employees may have had sensitive personal data stolen, including Social Security numbers, banking details and tax records, after attackers exploited a zero-day flaw in Oracle's PeopleSoft software.
About this happening:
Nissan disclosed a data leak affecting current and former employees after attackers exploited Oracle PeopleSoft, exposing sensitive payroll and identity records ac...
Nissan employee data leak via Oracle PeopleSoft zero-day
Data LeakHow related: Nissan has disclosed that current and former employees may have had sensitive personal data stolen, including Social Security numbers, banking details and tax records, after attackers exploited a zero-day flaw in Oracle's PeopleSoft software.
About this happening: Nissan disclosed a data leak affecting current and former employees after attackers exploited Oracle PeopleSoft, exposing sensitive payroll and identity records ac...
Nissan hit by network compromise
Incident
H score48
First: 29.06.2026 23:40
Last: 29.06.2026 23:40
Sources 1
How related:
Nissan has disclosed that current and former employees may have had sensitive personal data stolen, including Social Security numbers, banking details and tax records, after attackers exploited a zero-day flaw in Oracle's PeopleSoft software.
About this happening:
Nissan disclosed a data breach affecting current and former employees after unauthorized access tied to Oracle PeopleSoft exploitation put personnel records at ris...
Nissan hit by network compromise
IncidentHow related: Nissan has disclosed that current and former employees may have had sensitive personal data stolen, including Social Security numbers, banking details and tax records, after attackers exploited a zero-day flaw in Oracle's PeopleSoft software.
About this happening: Nissan disclosed a data breach affecting current and former employees after unauthorized access tied to Oracle PeopleSoft exploitation put personnel records at ris...
Oracle PeopleSoft broad zero-day exploitation campaign
Exploitation Wave
H score82
First: 29.06.2026 13:00
Last: 29.06.2026 13:00
Sources 1
About this happening:
A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...
Oracle PeopleSoft broad zero-day exploitation campaign
Exploitation WaveAbout this happening: A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...
Infinite Campus hit by data theft breach linked to ShinyHunters
Incident
H score51
First: 15.06.2026 15:38
Last: 15.06.2026 15:38
Sources 1
About this happening:
Infinite Campus suffered a Salesforce data theft breach that exposed more than 137,000 school staff accounts, putting staff contact and account data at risk. The compr...
Infinite Campus hit by data theft breach linked to ShinyHunters
IncidentAbout this happening: Infinite Campus suffered a Salesforce data theft breach that exposed more than 137,000 school staff accounts, putting staff contact and account data at risk. The compr...
Council of Europe ShinyHunters data leak claim
Data Leak
H score82
First: 15.06.2026 13:44
Last: 15.06.2026 13:44
Sources 1
About this happening:
ShinyHunters has posted the Council of Europe on a Tor-based leak site, claiming a data theft that could expose more than 297 GB and over 429,000 files. The al...
Council of Europe ShinyHunters data leak claim
Data LeakAbout this happening: ShinyHunters has posted the Council of Europe on a Tor-based leak site, claiming a data theft that could expose more than 297 GB and over 429,000 files. The al...
Timeline
-
29.06.2026 23:40 2 articles · 16d ago
Nissan discloses employee data breach tied to Oracle PeopleSoft attacks
Victim Impact UpdateNissan says attackers exploited an Oracle PeopleSoft vulnerability in a ShinyHunters-linked campaign and that the company was specifically targeted, with personal information for current and former employees in the United States, Canada, Mexico, and Brazil potentially exposed. Nissan says the material may include employee contact information, banking information, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary information, and the company has activated incident response, engaged external cybersecurity experts, secured affected systems, and is working with Oracle.
Show sources
- Nissan discloses employee data breach linked to Oracle zero-day attacks — www.bleepingcomputer.com — 29.06.2026 23:40
- Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day — www.infosecurity-magazine.com — 30.06.2026 19:00
-
11.06.2026 23:29 1 articles · 1mo ago
ShinyHunters exploits Oracle PeopleSoft zero-day
Exploitation ObservedGoogle's Mandiant says the UNC6240 cluster used CVE-2026-35273, a PeopleSoft Enterprise PeopleTools zero-day, to break into Oracle PeopleSoft systems and steal data between May 27 and June 9. Oracle did not publish its advisory until June 10, so the flaw remained unpatched throughout the activity window.
Show sources
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities — thehackernews.com — 11.06.2026 23:29
-
10.06.2026 21:31 2 articles · 1mo ago
Oracle PeopleSoft customers receive ShinyHunters extortion demands
Initial DisclosureOracle PeopleSoft cloud and on-premises customer instances were identified as targets of widespread data theft attacks, and affected customers were receiving extortion demands signed by the ShinyHunters extortion gang.
Show sources
- Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks — www.bleepingcomputer.com — 10.06.2026 21:31
- Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks — www.bleepingcomputer.com — 10.06.2026 21:31
-
10.06.2026 21:31 1 articles · 1mo ago
ShinyHunters claims data theft from 300 Oracle PeopleSoft instances
Attribution UpdateShinyHunters confirmed it was behind the Oracle PeopleSoft attacks and claimed stolen data from 300 instances across more than 100 organizations, saying the operation used a gadget chain of old and zero-day vulnerabilities and that success varied by instance configuration.
Show sources
- Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks — www.bleepingcomputer.com — 10.06.2026 21:31