Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1451+ Articles
151+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities
ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities
NEWS

ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities

The ShinyHunters group, tracked by Mandiant as UNC6240, has been exploiting CVE-2026-35273 in Oracle PeopleSoft to breach universities and higher...

Dylan H.

News Desk

June 11, 2026
4 min read

The ShinyHunters extortion group has been exploiting a critical zero-day vulnerability in Oracle PeopleSoft (CVE-2026-35273) to breach universities and higher education institutions, according to analysis by Google's Mandiant. The campaign leverages unauthenticated remote code execution to steal sensitive student, financial, and HR data before demanding payment to suppress publication.

Attribution: UNC6240

Mandiant attributes the PeopleSoft exploitation campaign to UNC6240, the designation it uses to track ShinyHunters. Mandiant has dated activity to a window predating Oracle's public disclosure, indicating the group had access to the vulnerability — or independently discovered it — before defenders had any warning.

UNC6240/ShinyHunters is a financially motivated threat actor with a long history of high-impact data theft operations targeting organizations where bulk personal data can be monetized through extortion or sold to other criminals. Past targets have included major retailers, telecom providers, and financial institutions. The pivot to targeting higher education via PeopleSoft represents a deliberate expansion into a sector with concentrated personal data and often under-resourced security teams.

Why Universities?

Oracle PeopleSoft Campus Solutions is one of the dominant student information system (SIS) platforms at North American and European universities. A single PeopleSoft instance at a large university may contain:

  • Student records for tens of thousands of current and former students
  • Social Security numbers, dates of birth, and home addresses
  • Financial aid and payment history
  • Academic transcripts and enrollment records
  • Faculty and staff HR data

This makes universities exceptionally attractive targets for data extortion — the potential for embarrassment, regulatory penalties, and harm to students creates strong pressure to pay.

The Double Extortion Model

UNC6240's campaign follows the classic double extortion playbook:

  1. Exploit CVE-2026-35273 to gain unauthenticated remote code execution on the PeopleSoft server
  2. Move laterally through connected systems to maximize data access
  3. Exfiltrate bulk datasets — student records, HR files, financial data
  4. Contact the victim with proof of the data theft and a payment demand
  5. Publish or auction data on dark web forums if the ransom is not paid

ShinyHunters maintains a dark web presence where stolen datasets are advertised and sold, giving victims a visible deadline and adding credibility to the extortion threat.

CVE-2026-35273: Technical Context

CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft Suite. Unauthenticated RCE flaws are among the most severe class of vulnerabilities — they require no credentials and allow an attacker on the network (or internet, if the service is exposed) to execute arbitrary commands on the target system.

PeopleSoft web portals are frequently internet-exposed to support remote student and staff access, dramatically expanding the attack surface. Organizations that have not yet applied Oracle's interim mitigation and restricted exposure are at immediate risk.

Recommended Actions for Higher Education

Institutions running Oracle PeopleSoft should take the following steps immediately:

  • Apply Oracle's emergency mitigation for CVE-2026-35273 without waiting for the next scheduled patch cycle
  • Restrict internet exposure of PeopleSoft portals where possible — VPN or IP allowlisting for admin interfaces
  • Review application logs for indicators of unauthorized access, particularly failed authentication attempts and unusual data export activity
  • Engage your IR team if any suspicious activity is found — ShinyHunters moves quickly from initial access to exfiltration
  • Notify legal and compliance teams so they are prepared in the event data was accessed

Broader Implications

The targeting of higher education through an enterprise ERP zero-day highlights a persistent challenge: large universities often maintain complex, legacy-adjacent software stacks where patching velocity is lower than in commercial enterprises. ShinyHunters and similar groups actively scan for these gaps.

The higher education sector should treat this campaign as a wake-up call to reassess the exposure and patching status of all internet-facing enterprise applications, not just PeopleSoft.

#Zero-Day#CVE#Data Breach#ShinyHunters#Higher Education#Oracle#Mandiant

Related Articles

ShinyHunters Uses Oracle Zero-Day to Rampage Higher Education

The ShinyHunters hacking group exploited a critical Oracle PeopleSoft ERP zero-day (CVE-2026-35273) that disproportionately impacted American...

6 min read

Oracle Mitigates PeopleSoft Zero-Day Exploited in Data Theft Attacks

Oracle has issued an emergency mitigation for CVE-2026-35273, a critical unauthenticated RCE flaw in PeopleSoft Suite being actively exploited by the...

3 min read

Google Confirms ShinyHunters Exploited Oracle PeopleSoft Zero-Day CVE-2026-35273

Google's Threat Intelligence Group confirmed in-the-wild exploitation of Oracle PeopleSoft zero-day CVE-2026-35273 by ShinyHunters, even as Oracle declined to publicly acknowledge the exploitation.

5 min read
Back to all News