In the recurring drama between those who guard and those who breach, a hacking collective known as ShinyHunters has reminded the world that a locked window is not the same as a sealed one. Google's Mandiant division has documented a second wave of attacks against Oracle's PeopleSoft software — systems that quietly manage the payroll, benefits, and personnel records of institutions across six continents — after the group studied the defenses erected against its first campaign and found a way through them. The breach, spanning universities, hospitals, government agencies, and more, arrives along
ShinyHunters expands PeopleSoft attacks after bypassing Oracle defenses
A firewall rule can slow attackers down, but only a genuine code fix closes the underlying hole.
So ShinyHunters attacked in May and June, got stopped, and then just came back with a new approach?
Not exactly stopped—they were slowed down. Organizations put up firewalls after the first attacks, but that's not the same as fixing the actual bug in the software.
Right, and that's the key detail here. A firewall rule is a temporary barrier. The real fix is Oracle's patch. ShinyHunters figured out that many places had the barrier but not the patch.
How many organizations are we talking about?
Mandiant said dozens of systems globally, across six different sectors. Universities, hospitals, tech companies, government agencies.
But "dozens" is vague. We don't know if that's 30 or 300. And Mandiant didn't name any of the victims, so we can't actually verify the scope independently.
What about the FBI claim? Did ShinyHunters actually get into the FBI?
They said they did. They claim they have names of FBI personnel from sensitive units, plus medical and psychiatric records.
But Reuters couldn't verify it. The FBI said it's investigating, but that's not confirmation. We have to sit with the uncertainty here.
Why would ShinyHunters announce this if they weren't sure they had it?
Reputation, maybe. These groups operate in a kind of underground economy. Proving you can breach major targets is currency.
Or it's a bluff. Or it's partial truth—they got something, but maybe not everything they're claiming. The reporting is honest about what we don't know, which is important.
O Pulso
- ShinyHunters did not retreat after its first wave of PeopleSoft attacks in May and June — it studied the defenses and engineered a path around them.
- Firewall rules, deployed by dozens of organizations as a stopgap, proved insufficient against a group that understood the gap between interim protection and an actual code fix.
- The renewed campaign has now reached higher education, healthcare, government, agriculture, transportation, and technology sectors across six continents — a scope that signals methodical targeting, not opportunistic scanning.
- ShinyHunters has claimed access to FBI personnel records, including names of staff in sensitive units and medical and psychiatric files, a claim the bureau has not confirmed but says it is 'aggressively investigating.'
- Oracle's patch exists — the urgent question is how many institutions are still running unprotected systems, and whether this second wave will finally compel the patching that closes the vulnerability for good.
In the recurring drama between those who guard and those who breach, a hacking collective known as ShinyHunters has reminded the world that a locked window is not the same as a sealed one. Google's Mandiant division has documented a second wave of attacks against Oracle's PeopleSoft software — systems that quietly manage the payroll, benefits, and personnel records of institutions across six continents — after the group studied the defenses erected against its first campaign and found a way through them. The breach, spanning universities, hospitals, government agencies, and more, arrives alongside an unverified claim that FBI personnel data, including sensitive medical and psychiatric records, may have been taken. What unfolds here is not merely a technical failure but a lesson in the difference between the appearance of security and its substance.
Google's Mandiant division released a report detailing a resurgence of coordinated attacks against Oracle's PeopleSoft software by the hacking collective ShinyHunters — a group that has shown a troubling capacity to adapt when defenders push back.
The first campaign ran from late May into early June, targeting universities through a specific flaw in PeopleSoft's code. Oracle responded with patches and guidance, and many organizations deployed web application firewall rules to block similar intrusions. ShinyHunters, rather than moving on, studied those defenses and found a way around them.
The second wave, documented by Mandiant, focused precisely on organizations that had installed firewall protections but had not yet applied Oracle's actual software patch. The distinction is consequential: a firewall rule can slow an attacker; only a genuine code fix closes the underlying hole. Across dozens of systems on six continents, ShinyHunters breached networks in higher education, technology, healthcare, agriculture, transportation, and government — a scope that suggests deliberate, methodical targeting.
Days before the report's release, the group claimed to have accessed FBI personnel data, including records from sensitive units and medical and psychiatric files. The FBI said it was 'aggressively investigating' the reported breach. Oracle declined to comment.
PeopleSoft sits at the center of critical institutional functions — payroll, benefits, personnel records — for thousands of organizations worldwide. The window between public awareness of a flaw and actual patching can stretch for weeks or months, and ShinyHunters has demonstrated it understands how to exploit that interval. For institutions still running unpatched systems, the lesson is plain: the defenses that seemed to contain the summer attacks were never a permanent answer.
Google's threat intelligence division released a report on Friday detailing a resurgence of coordinated attacks against Oracle's PeopleSoft software, carried out by the hacking collective known as ShinyHunters. The group, which has claimed responsibility for multiple significant data breaches in recent months, has demonstrated a troubling ability to adapt its methods after initial defensive measures were deployed.
The first wave of attacks occurred between late May and early June, primarily targeting universities. ShinyHunters exploited a specific vulnerability in PeopleSoft's code to gain unauthorized access to systems. Following those incidents, Oracle issued guidance and security patches, and many organizations implemented web application firewall rules designed to block similar intrusions. But the group did not abandon its campaign. Instead, it studied the defenses that had been erected and found a path around them.
The renewed assault, documented by Mandiant—Google's cybersecurity unit—shows ShinyHunters targeting organizations that had installed the firewall protections but had not yet applied Oracle's actual software patch. The distinction matters: a firewall rule can slow attackers down, but only a genuine code fix closes the underlying hole. Across dozens of systems spanning six continents, the group successfully breached networks in higher education, technology, healthcare, agriculture, transportation, and government sectors. The scope and diversity of targets suggest an operation conducted with methodical precision rather than opportunistic scanning.
The timing of the disclosure carries particular weight. Days before Mandiant's report, ShinyHunters announced that it had accessed data belonging to the Federal Bureau of Investigation, claiming to have obtained personnel records from sensitive units along with medical and psychiatric files. Reuters has not independently verified this claim, and the FBI, in a statement issued Wednesday, said only that it was "aggressively investigating" the reported breach. Oracle declined to comment on the matter.
The situation underscores a persistent vulnerability in how organizations defend themselves against sophisticated attackers. PeopleSoft handles critical functions—payroll, benefits administration, personnel records—for thousands of institutions worldwide. When a flaw is discovered, the window between public awareness and actual patching can stretch for weeks or months. Defenders must choose between implementing interim protections or waiting for a permanent fix. ShinyHunters has shown it understands this calculus, and it is willing to exploit the gap.
For organizations still running unpatched versions of PeopleSoft, the message is stark: the vulnerability that seemed contained after the summer attacks has proven far from dormant. The group's ability to pivot its tactics suggests that even well-resourced institutions—universities with dedicated IT staff, government agencies with security budgets—cannot assume that initial defensive measures will hold indefinitely. The question now is how many systems remain exposed, and whether the latest round of attacks will finally prompt the kind of urgent patching that closes the door entirely.
Citações Notáveis
The FBI said it was 'aggressively investigating' the reported breach of personnel data.— Federal Bureau of Investigation, statement issued Wednesday