Google: ShinyHunters Hit 100+ Orgs in PeopleSoft Zero‑Day; 68% Were US Universities
Key Takeaways
- Google and Mandiant confirm active exploitation of CVE-2026-35273, a critical unauthenticated RCE flaw in Oracle PeopleSoft.
- The ShinyHunters group compromised roughly 300 instances, with the higher education sector bearing 68% of the impact.
- Oracle has only released mitigations, leaving organizations exposed to data theft and extortion.
Mentioned
Key Intelligence
Key Facts
- 1Google confirmed exploitation of PeopleSoft zero‑day CVE-2026-35273 by ShinyHunters (UNC6240) between May 27 and June 9, 2026, targeting ~300 instances across 100+ organizations.
- 2Oracle released mitigations only—no full patch is currently available—for PeopleTools 8.61, 8.62, and affected Enterprise Applications.
- 368% of the notified organizations were in the US higher education sector; the University of Nottingham is the first publicly confirmed victim.
- 4Attackers deployed customized MeshCentral agents masquerading as cloud endpoints for persistent access and lateral movement.
- 5Mandiant CTO Charles Carmakal confirmed zero‑day exploitation and warned of the severity.
- 6ShinyHunters previously targeted Salesforce customers in a massive data‑theft campaign, signalling a pattern of attacking major SaaS/ERP platforms.
Who's Affected
Analysis
For cybersecurity professionals, the PeopleSoft zero‑day is a stark reminder that ERP systems are not just back‑office utilities—they are prime extortion targets. ShinyHunters’ methodical campaign, leveraging custom MeshCentral agents and lateral movement scripts, illustrates a growing trend of attackers treating enterprise applications like data goldmines. With Oracle’s patch still missing, understanding the attack chain and the group’s shifting focus toward education is critical for defense.
In a concerning development for enterprise security, Google has officially confirmed that the ShinyHunters hacker group exploited a critical zero-day vulnerability in Oracle PeopleSoft between May 27 and June 9, 2026. The flaw, tracked as CVE-2026-35273, allows unauthenticated remote code execution and affects PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, as well as PeopleSoft Enterprise Applications. Oracle released an out-of-band security advisory on June 11 but, notably, has only provided mitigations rather than a complete patch, heightening the urgency for thousands of organizations globally. The attacks focused disproportionately on the higher education sector, with Google notifying more than 100 global organizations of potential compromise, 68% of which were universities and colleges in the United States. The University of Nottingham is the first confirmed victim. This incident underscores the persistent threat posed by financially motivated cybercriminal groups and the growing risk to ERP systems that house sensitive HR, payroll, and financial data.
In a concerning development for enterprise security, Google has officially confirmed that the ShinyHunters hacker group exploited a critical zero-day vulnerability in Oracle PeopleSoft between May 27 and June 9, 2026.
PeopleSoft is a cornerstone of enterprise operations for large organizations, managing everything from employee records to supply chain logistics. The unauthenticated RCE nature of CVE-2026-35273 means that attackers can gain initial access without any credentials, making it particularly dangerous for internet-facing systems. ShinyHunters, designated UNC6240 by Google’s Threat Intelligence Group, is notorious for high‑volume data theft and extortion campaigns, previously targeting Salesforce customers in a similar fashion. The group’s claim of compromising approximately 300 PeopleSoft instances across 100 organizations suggests a well‑coordinated, automated attack campaign. Mandiant’s incident response teams corroborated the exploitation, with CTO Charles Carmakal issuing warnings about the zero‑day activity.
Technical details from Mandiant and Google’s joint research reveal a sophisticated attack chain. After gaining access via the zero‑day, threat actors deployed customized MeshCentral agents masquerading as legitimate cloud endpoints, which enabled persistent remote access and administrative command execution. They then used a custom lateral movement and defacement script named [victim_abbreviation]_fanout.sh to propagate within victim environments, indicating an intent not only to exfiltrate data but also to potentially disrupt operations or leave a visible calling card. The staging environments and use of legitimate remote management tools obscured malicious traffic, evading many traditional security controls.
The targeting of the education sector is notable. Universities often manage large, complex PeopleSoft implementations for student information, human resources, and financial management, yet they frequently operate with limited cybersecurity budgets and legacy infrastructure. Publicly, ShinyHunters hinted at the stolen data being used for extortion, a recurring modus operandi that involves threatening to leak sensitive personal and financial records unless a ransom is paid. For institutions that fall under regulations like GDPR or FERPA, such breaches can incur massive fines and reputational damage.
What to Watch
From a market and industry perspective, Oracle’s delayed full patch rollout—opting first for mitigations—may strain customer trust. The company’s advisory emphasizes immediate implementation of those mitigations as a high‑priority risk reduction measure, but security practitioners may question the completeness of the fix. Oracle’s stock (ORCL) could see volatility if investors worry about potential liability or customer churn; Google, while not directly affected, may face scrutiny over its role in identifying and disclosing the attacks. The incident also highlights the value of collaborative threat intelligence: Google’s quick notification to over 100 organizations likely prevented further spread.
Looking ahead, organizations running PeopleSoft should urgently apply Oracle’s mitigations and review logs for any signs of MeshCentral agent deployments from May 27 onward. The education sector must particularly reassess its ERP security posture, possibly accelerating cloud migration where vendor-managed patching can alleviate internal resource constraints. More broadly, the attack reinforces a grim trend: ERP systems are becoming prime targets for ransomware and data‑theft groups because they contain consolidated, high‑value data. As ShinyHunters and similar actors refine their techniques, defenders must prioritize both vulnerability management and network segmentation to contain such threats.
Timeline
Timeline
Zero‑Day Exploitation Begins
According to Google and Mandiant, ShinyHunters starts actively exploiting CVE-2026-35273 to compromise PeopleSoft instances.
Attack Campaign Window
ShinyHunters targets ~300 instances across 100+ organizations, focusing on education sector. Deploys MeshCentral agents and lateral movement scripts.
Oracle Releases Out‑of‑Band Advisory
Oracle publishes mitigations for CVE-2026-35273 and warns customers to apply them immediately, but no full patch is provided.
Google Confirms Exploitation
Google Threat Intelligence Group publicly confirms zero‑day exploitation by ShinyHunters and notifies over 100 affected organizations.
Sources
Sources
Based on 2 source articles- SecurityWeekOracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day AttacksJun 11, 2026
- SecurityWeekGoogle Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHuntersJun 12, 2026
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |