Oracle has warned customers about a critical vulnerability in its PeopleSoft software after cybercrime group ShinyHunters claimed it used the flaw to breach more than 100 organizations.
The security advisory was issued on Thursday, a day after the hackers publicly took responsibility for the campaign.
Unpatched flaw exploited remotely
Oracle said the vulnerability can be exploited over the internet without requiring authentication.
At the time of publication, the company had not released a patch.
Instead, Oracle urged customers using PeopleSoft to implement mitigation measures to reduce the risk of exploitation.
The flaw is considered a zero-day vulnerability, meaning it was discovered and exploited before Oracle had an opportunity to fix it.
Mandiant links attacks to same vulnerability
Mandiant, Google’s cybersecurity division, said the bug identified by Oracle is the same one being exploited by ShinyHunters.
The security firm said it has contacted more than 100 organizations worldwide, most of them in the United States, to help secure potentially vulnerable systems.
According to Mandiant:
- About two-thirds of the organizations are in the higher education sector.
- Some institutions blocked the attacks or remediated the vulnerability.
- Others suffered breaches that led to stolen data being published on ShinyHunters’ leak site.
“While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters [Data Leak Website],” Mandiant said in a blog post.
Hackers claim theft of student records
A member of ShinyHunters told TechCrunch that universities and colleges were among the victims.
The hacker shared a message allegedly sent to one affected school claiming that the attackers had stolen “hundreds of thousands of student records.”
According to the message, the data included:
- Full names.
- Home addresses.
- Phone numbers.
- Email addresses.
- Dates of birth.
- Gender and ethnicity information.
- Enrollment status.
- GPA details.
- Majors.
- Student identification numbers.
TechCrunch reported that Oracle did not respond to requests for comment.
Pattern of software-based attacks
PeopleSoft and its users are the latest targets in a series of campaigns in which ShinyHunters has focused on organizations using common software platforms.
Over the past year, the group has targeted companies using:
- Salesforce.
- Gainsight.
- Software from education technology company Instructure.
Attackers typically seek to steal customer or corporate data and threaten to publish it unless a ransom is paid.
Previous attacks on Instructure
Earlier this year, Instructure said it paid the hackers after its systems were breached twice.
During that campaign, ShinyHunters also defaced login pages belonging to schools using the company’s Canvas platform.
TL;DR
Oracle has disclosed a critical, unpatched vulnerability in PeopleSoft software that hackers from ShinyHunters allegedly used to breach more than 100 organizations. Mandiant said many of the affected entities are universities and colleges.
AI summary
- Oracle disclosed a critical PeopleSoft vulnerability.
- ShinyHunters claims to have breached more than 100 organizations.
- Mandiant linked the attacks to the same flaw.
- Many affected organizations are in higher education.
- Oracle has not yet released a patch.








