Google flags ShinyHunters attacks on Oracle PeopleSoft zero-day
Google's Threat Intelligence Group and Mandiant attributed a zero-day exploit campaign against Oracle PeopleSoft to the hacking group ShinyHunters. Active between May 27 and June 9, the attacks utilized customized MeshCentral agents to target over 100 organizations, primarily in higher education, before Oracle released a security advisory on June 10. ShinyHunters has a history of extortion, including recent attacks on Instructure and Rockstar Games via Snowflake.

*this image is generated using AI for illustrative purposes only.
Alphabet Inc.'s cybersecurity teams have identified an ongoing cyber extortion campaign targeting Oracle Corp.'s PeopleSoft enterprise software, attributing the activity to the hacking group ShinyHunters. Researchers at the Google Threat Intelligence Group and Mandiant revealed that the attackers exploited a previously unknown vulnerability in Oracle's enterprise resource planning platform. Since Oracle had not yet released a patch at the time, the vulnerability was exploited as a zero-day, allowing attackers to gain access to exposed systems.
The campaign was active between May 27 and June 9. PeopleSoft is widely used by organizations to manage human resources, finance, and supply-chain operations, making it a high-value target for cybercriminals. The exploitation occurred before Oracle released a security advisory on June 10, meaning organizations had no available fix during the attack window.
Attack Mechanics and Impact
Researchers reported that the attackers deployed customized MeshCentral agents disguised as legitimate cloud services. These tools allowed them to execute administrative commands and maintain covert access to compromised environments. Google stated that it notified more than 100 organizations whose systems appeared vulnerable, with the majority based in the U.S. About 68% of the affected entities were in the higher education sector.
Sector-Specific Targets
The following table outlines the distribution of affected entities based on the data provided by Google:
| Sector | Percentage of Affected Entities |
|---|---|
| Higher Education | 68% |
| Other Sectors | 32% |
ShinyHunters is known for previous extortion campaigns against global firms. The group recently targeted education software provider Instructure in a separate incident. In April, ShinyHunters took responsibility for stealing nearly 80 million records from Rockstar Games by exploiting a third-party security flaw tied to cloud platform Snowflake Inc. and analytics firm Anodot.
Market Reaction
Alphabet Inc. Class A (GOOGL) rose 1.15% to $361.87 in Friday's pre-market trading, while Class C (GOOG) gained 0.96% to $360.
How will the delayed patch release impact Oracle's customer retention and trust in the PeopleSoft platform?
Will the heavy targeting of the higher education sector lead to increased regulatory scrutiny or cybersecurity funding for universities?
Could this incident trigger a broader sell-off in Oracle's stock as investors assess potential liability and remediation costs?





























