← Back to list

ShinyHunters Is Back. This Time the Entry Point Is More Dangerous

A critical PeopleSoft zero-day, stolen university data, and law enforcement wins show the contrast in this week’s cyber landscape.

AmieOnSecurity · 2026-06-14 03:27 · 0 claps · 5.9 min read
#amieonsecurity #cybersecurity #third-party-risk #shinyhunters
Open on Medium ↗
Wiki topics: EDU · Education & Learning 🔒 · Cybersecurity ⚖️ · Law & Justice

ShinyHunters Is Back. This Time the Entry Point Is More Dangerous

A critical PeopleSoft zero-day, stolen university data, and law enforcement wins show the contrast in this week’s cyber landscape.

A Familiar Name, A Different Target

If you followed my coverage of the Canvas breach in May, the name ShinyHunters needs no introduction. The same group that disrupted learning for millions of students during finals week has returned this week with a different target and a significantly more dangerous entry point.

ShinyHunters exploited a critical zero-day vulnerability in Oracle PeopleSoft to breach more than 100 organizations across approximately 300 PeopleSoft instances. The group has already published stolen data from at least one confirmed victim: the University of Nottingham. That breach exposed the personal and academic records of nearly 454,600 current and former students.

Mandiant and Google’s Threat Intelligence Group confirmed the campaign ran between May 27 and June 9. Oracle did not publish its advisory until June 10, meaning every organization hit during those two weeks was dealing with a zero-day: a flaw for which no patch existed and no official warning had been issued.

What PeopleSoft Is and Why This Matters

Oracle PeopleSoft is not a system most people outside of IT or finance have heard of. But it underpins the daily operations of some of the world’s largest and most data-sensitive organizations.

PeopleSoft serves as an enterprise resource planning backbone for universities, hospitals, and government agencies worldwide, consolidating HR records, payroll data, financial information, and student administration records into a single, integrated system that administrators and employees rely on for daily operations.

That is the reason ShinyHunters targeted it. One successful breach does not expose a single application. It exposes everything that flows through that system.

The Zero-Day and How It Was Used

The vulnerability, tracked as CVE-2026–35273, is a remote code execution flaw in PeopleSoft Enterprise PeopleTools rated 9.8 out of 10 on the severity scale. It requires no login and no user interaction. An attacker with HTTP-based network access can take complete control of an affected server.

The technical approach ShinyHunters used made this attack harder to detect than a straightforward exploit. Like many enterprise platform vulnerabilities, the issue became significantly more dangerous when administrative components were directly reachable from the internet. Rather than relying on a single vulnerability, the group chained CVE-2026–35273 together with older known flaws in what is called a gadget chain, a technique that links multiple vulnerabilities to produce exploitation that neither component enables on its own.

After gaining initial access, the attackers deployed a customized version of MeshCentral, an open-source remote monitoring and management tool, disguised as legitimate Microsoft Azure services. This gave them persistent access to compromised systems while appearing to blend into normal enterprise traffic.

Mandiant’s CTO Charles Carmakal confirmed active exploitation in the wild. Google’s Threat Intelligence Group notified more than 100 global organizations whose IP addresses correlated with potentially vulnerable endpoints. While several organizations successfully blocked the activity or remediated the vulnerability, others experienced compromise, with stolen data subsequently published on the ShinyHunters data leak site. The group has publicly indicated that contact with victims has only just begun. More disclosures are expected.

The Education Pattern Is Not Accidental

Sixty-eight percent of the organizations Mandiant identified as potentially affected were universities and colleges, most of them based in the United States.

This is the second time in six weeks that ShinyHunters has hit the education sector. The Canvas breach in May disrupted student access during finals week. The Oracle PeopleSoft campaign exposed student records, payroll data, and academic information at universities that were unknowingly vulnerable for nearly two weeks before a patch was available.

Education is not being targeted randomly. Universities run complex technology environments with limited security staffing, high volumes of sensitive data, a constant influx and outflow of new users, and an operational culture that prioritizes access and openness. That combination makes them consistently attractive to extortion groups seeking large data sets and to organizations under pressure to keep systems running.

If your institution uses Oracle PeopleSoft, the immediate action is to apply Oracle’s out-of-band advisory for CVE-2026–35273, restrict external access to the Environment Management Hub endpoints if that has not already been done, review logs for any activity consistent with this campaign going back to May 27, and check for any unauthorized installations of remote monitoring tools on PeopleSoft hosts.

Law Enforcement Struck Back This Week Too

The ShinyHunters’ story is serious. But it did not happen in a vacuum, and this week also produced two meaningful enforcement wins that deserve recognition alongside the threat coverage.

On June 10, an international operation led by the US Secret Service, IRS Criminal Investigation, and Polish law enforcement, with support from Europol and Eurojust, dismantled AudiA6, a cryptocurrency laundering service estimated to have processed more than 336 million euros in illicit funds for ransomware gangs and cybercriminal networks between 2022 and 2025. Two alleged administrators were arrested in Georgia. Authorities seized more than 30 servers, took down 25 domains, froze nearly 692,000 euros in cryptocurrency, and confiscated more than 80 vehicles and multiple properties.

AudiA6 was linked to more than 15 international cybercrime investigations, including proceeds from the 2022 LastPass breach. The operation also took down Dark2Web, a dark web cybercrime forum used to advertise illicit services and connect criminal actors worldwide.

Separately, INTERPOL’s Operation Ramz, conducted across 13 countries in the Middle East and North Africa between October 2025 and February 2026, resulted in 201 arrests and the disruption of Sniper Dz, a phishing-as-a-service platform that had collected more than 45,000 victim records over a decade. The platform’s primary developer and administrator was arrested by the Algerian National Police.

These are not symbolic wins. Dismantling the financial infrastructure that makes cybercrime profitable, arresting operators and seizing assets across multiple jurisdictions, and shutting down platforms that lower the barrier to entry for less sophisticated attackers all reduce the overall capability of the criminal ecosystem. They do not eliminate the threat, but they impose real costs and disruption on criminal networks that have operated with relative impunity.

The Reality of the Cat and Mouse

ShinyHunters breached more than 100 organizations through an unpatched zero-day while law enforcement was simultaneously dismantling the financial pipeline ransomware groups depend on. Both things are true at the same time. That is what the cybersecurity landscape looks like in practice: persistent, well-organized criminal groups continuing to find and exploit entry points while enforcement operations work through the slow, methodical process of building cases and coordinating across borders.

The lesson for organizations is not to wait for enforcement to solve the problem. Enforcement creates friction for criminal ecosystems. It does not eliminate the threat facing any individual institution. The responsibility for protecting sensitive data, limiting external exposure of critical enterprise systems, and maintaining current patches remains with the organization regardless of what law enforcement is doing.

In my professional view, the Oracle PeopleSoft campaign is one of the most instructive incidents of 2026 so far, not because the attack method is new, but because of what it reveals about where organizations remain vulnerable. PeopleSoft instances that had their Environment Management Hub exposed to the internet were not breached because of a sophisticated, targeted attack. They were breached because a known type of architectural exposure, an administrative interface reachable from outside the network, met an attacker with the right tool at the right moment. That combination does not require nation-state resources or advanced tradecraft. It requires patience, a working exploit, and a list of exposed endpoints. The organizations that were not breached were the ones that had already reduced that exposure. That is always the most important security investment: making yourself a harder target before the exploit exists.

Cybersecurity #ShinyHunters #OraclePeopleSoft #VulnerabilityManagement #ThreatIntelligence #CyberRisk #HigherEducation #InformationSecurity #SecurityOperations #CyberDefense #AmieOnSecurity


Reference Links

The Hacker News, ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities: https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html

Google Cloud Blog, Mandiant: ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit: https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit

The Register, ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft zero-day: https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-claims-oracle-peoplesoft-0-day-hit-100-orgs/5254443

Student and alumni data has been compromised in a data security incident: https://www.nottingham.ac.uk/currentstudents/news/student-and-alumni-data-has-been-compromised-in-a-data-security-incident

SecurityWeek, Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks: https://www.securityweek.com/oracle-addresses-peoplesoft-vulnerability-amid-reports-of-zero-day-attacks/

Security Affairs, Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign: https://securityaffairs.com/193543/cyber-crime/oracle-peoplesoft-rce-flaw-used-as-zero-day-in-ongoing-shinyhunters-campaign.html

Black Kite, ShinyHunters Hit Oracle PeopleSoft and Your Vendors May Already Be Compromised: https://blackkite.com/blog/shinyhunters-hit-oracle-peoplesoft-and-your-vendors-may-already-be-compromised

The Hacker News, Europol Disrupts AudiA6 Crypto Laundering Service: https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html

Help Net Security, Authorities dismantle AudiA6 crypto laundering service: https://www.helpnetsecurity.com/2026/06/12/europol-audia6-crypto-laundering-service-ransomware-groups/

BleepingComputer, Authorities dismantle AudiA6 ransomware crypto-laundering service: https://www.bleepingcomputer.com/news/legal/authorities-dismantle-audia6-ransomware-crypto-laundering-service/


메타데이터
post_id
c6fcdfce5a3e
slug
shinyhunters-is-back-this-time-the-entry-point-is-more-dangerous-c6fcdfce5a3e
url
https://medium.com/@amieonsecurity/shinyhunters-is-back-this-time-the-entry-point-is-more-dangerous-c6fcdfce5a3e
canonical_url
https://medium.com/@amieonsecurity/shinyhunters-is-back-this-time-the-entry-point-is-more-dangerous-c6fcdfce5a3e
author_url
https://medium.com/@amieonsecurity
status
ok
fetched_at
2026-06-21 19:25:17