Oracle Alerts on Critical Security Flaw Exploited by Hackers in Over 100 Businesses

Oracle has alerted its business clients regarding a serious vulnerability found in its PeopleSoft software, a tool utilized by major corporations for managing payroll and human resources. This warning follows claims from a cybercrime collective taking responsibility for exploiting this flaw during a widespread hacking incident.
The tech firm released this security advisory on Thursday after the hacking group, identified as ShinyHunters, announced that they had breached over 100 organizations utilizing PeopleSoft servers.
Mandiant, a cybersecurity firm owned by Google that specializes in investigating incidents of cyberattacks, highlighted in a blog post that the vulnerability identified by Oracle is the same one being exploited by the ShinyHunters group in targeting PeopleSoft clients.
As of now, Oracle has not issued a patch for this vulnerability. The advisory from the company indicated that the flaw can be exploited via the internet without any form of authentication, such as a password.
Oracle has recommended that users of PeopleSoft implement its suggested mitigations to safeguard against potential exploitation.
A member of the ShinyHunters group previously informed a tech outlet that their scheme involved taking advantage of an unpatched vulnerability in PeopleSoft servers. This particular flaw is classified as a zero-day because it was exploited before Oracle had the opportunity to address it.
Mandiant confirmed it has alerted over 100 organizations globally, primarily in the United States, to take measures to secure their potentially at-risk systems. According to their findings, a significant portion of these organizations operates in higher education, corroborating earlier claims by ShinyHunters.
Mandiant further stated, “While several organizations were able to thwart the intrusion or address the vulnerabilities, some did experience breaches, leading to the publication of stolen data on ShinyHunters’ Data Leak Website.”
Oracle did not respond to inquiries regarding the situation.
Contact Us
If you have additional insights about this hacking operation or any other data breaches, we would like to hear from you. Please reach out securely from a non-work device through Signal, Telegram, or Keybase.
According to a member of ShinyHunters, some of the hacked entities include universities and colleges.
The hacker provided a message purportedly sent to one affected educational institution, claiming to have extracted sensitive data on “hundreds of thousands of students, including full name, home address, phone number, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID across all campuses,” among other details.
PeopleSoft and its users have become the latest targets in a series of hacking campaigns orchestrated by ShinyHunters, which has a history of exploiting organizations that rely on the same vulnerable software.
Over the past year, this group has also focused on companies utilizing Salesforce, Gainsight, and software from the education sector giant Instructure, among others.
After identifying susceptible software and the entities using it, the hackers work to steal corporate or customer data, threatening to make it public unless a ransom is paid.
Earlier this year, Instructure acknowledged paying a ransom following two breaches of its systems. During these hacking incidents, ShinyHunters also defaced the login pages of numerous institutions that employ Instructure’s well-known school information portal, Canvas.



