Oracle PeopleSoft hacked: 100+ organisations hit – Claril Noticias

The notorious cybercrime group ShinyHunters compromised Oracle PeopleSoft servers at more than 100 global organisations, primarily universities, this Wednesday to exfiltrate vast amounts of sensitive student and administrative data.

The massive data breach, which was first reported by BleepingComputer, was confirmed to TechCrunch by a member of the hacking collective.

Mass Exploitation of Enterprise Software

This latest campaign underscores that ShinyHunters, currently one of the most active and visible cybercrime syndicates, is accelerating its operations by specialising in large-scale, automated attacks. Their established modus operandi involves identifying and exploiting a single vulnerability within widely used software to compromise dozens of high-value targets simultaneously.

What is Oracle PeopleSoft?

PeopleSoft is a widely deployed enterprise software suite used by major institutions to manage critical business operations, including payroll, human resources, general administration, and financial systems.

Highly Sensitive Data Exfiltrated

The scale of the data stolen during this campaign is extensive. According to a ransom message allegedly sent to one of the victims, the attackers managed to steal student, applicant, financial aid, immigration, health, and administrative records.

The compromised student records contain highly sensitive personally identifiable information (PII), including full names, home addresses, telephone numbers, email addresses, and dates of birth. Interestingly, the ShinyHunters representative noted that the majority of the targeted educational institutions had already been compromised in previous, unrelated cyber incidents.

Failed FBI Target and Swatting Denials

The hackers also revealed that their initial objective was far more ambitious: breaching an official FBI PeopleSoft server. The group intended to use the access to post a public statement denying any involvement in a recent wave of swatting incidents, which the FBI flagged in an alert last month. However, the spokesperson admitted that this specific attempt on the federal agency failed.

At the time of writing, Oracle has not responded to multiple requests for comment regarding the security breach.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *