ShinyHunters Tied to Fresh PeopleSoft Extortion Campaign

Medium · SecurityWeek ·

Key points

  • ShinyHunters is linked to a new extortion campaign involving Oracle PeopleSoft.
  • The group modified an exploit for CVE-2026-35273 and is using it in fresh attacks.
  • Google has issued a warning, while Oracle is the vendor for PeopleSoft fixes.
  • Severity guidance is medium, but unpatched systems remain at risk.

Google has issued a warning about a newly observed extortion push involving Oracle PeopleSoft. According to the alert, the ShinyHunters group has taken an existing exploit for CVE-2026-35273 and changed it, then used the altered code to go after the flaw in fresh attacks. The activity is being described as a new campaign rather than a continuation of older intrusions.

Organizations running PeopleSoft are the primary audience for this warning. Because PeopleSoft often supports HR, finance, student, and payroll workflows, a successful intrusion can expose sensitive records and create operational disruption. The extortion angle means attackers may not only seek data theft but also pressure victims with threats to leak or sell what they obtain.

The vulnerability is tracked as CVE-2026-35273, and the current severity guidance is medium. That rating should not be treated as permission to delay. A modified exploit can lower the skill required for copycat actors, and public warning from Google may accelerate scanning and attempts against unpatched systems.

Oracle is the vendor responsible for PeopleSoft fixes, while Google's involvement signals that threat intelligence or research teams are tracking the campaign. Administrators should verify whether their PeopleSoft deployment is affected, confirm patch levels, and review whether any exploitation indicators appear in logs.

Watch for increased probing of PeopleSoft endpoints, unexpected outbound traffic, new administrative accounts, and extortion-themed communications. If exploitation is suspected, preserve evidence, isolate affected systems, and engage incident response before restoring service.

What to do now

  1. Inventory all internet-facing and internal PeopleSoft instances, then map versions and patch levels against Oracle guidance for CVE-2026-35273.
  2. Apply Oracle's available patches, mitigations, or configuration workarounds immediately; if patching is delayed, isolate affected systems behind restricted access.
  3. Review PeopleSoft, web server, VPN, and identity logs for signs of exploit attempts, unusual file changes, new accounts, or data staging tied to ShinyHunters activity.
  4. Enforce MFA, least privilege, and network segmentation for PeopleSoft administrative and database access; remove unnecessary external exposure.
  5. Test offline backups and recovery procedures for PeopleSoft data, and verify that backups cannot be altered by compromised accounts.
  6. Brief security operations and help desk staff on the extortion campaign, including how to escalate suspected incidents and preserve forensic evidence.
  7. Monitor vendor and threat intel updates for changes to CVE-2026-35273 exploitation, ShinyHunters tactics, and any new indicators.

CVE references

  • CVE-2026-35273

Original source

SecurityWeek

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news