Oracle warns customers of critical attack on PeopleSoft after hundreds of servers hacked in apparent ShinyHunters data theft attacks



  • ShinyHunters is likely behind the CVE-2026-35273 attack on Oracle’s PeopleSoft
  • Versions 8.61 and 8.62 affected, users urged to take “immediate action”
  • Google’s Mandiant informed more than 100 organizations

Oracle PeopleSoft servers, used by universities, businesses and public sector organizations, are under a new attack by the ShinyHunters extortion group, researchers revealed.

The attackers claim to have compromised more than 100 organizations and exfiltrated data from around 300 PeopleSoft instances by exploiting a vulnerability identified as CVE-2026-35273.

Leave a Comment

Your email address will not be published. Required fields are marked *