In the quiet architecture of enterprise software that underpins universities, hospitals, and governments, a known wound has been left open long enough for determined hands to reach inside. ShinyHunters, a hacking collective tracked by Google's Mandiant division, has resumed a systematic campaign exploiting an unpatched Oracle PeopleSoft vulnerability across dozens of organizations in multiple countries — adapting their methods when defenses partially closed, and pressing forward where they did not. The breach claims now extend to FBI employee records and medical files, reminding us that in the
ShinyHunters resumes Oracle PeopleSoft exploitation across dozens of systems
Attackers refined their approach to bypass partial defenses
So ShinyHunters went after the same vulnerability twice—why would they do that if Oracle already published a fix?
Because most organizations don't patch immediately. They set up a firewall rule to block the attack while they plan the update. ShinyHunters just waited for those halfway-defended systems.
Right, but we should be clear: Mandiant documented the second wave. We don't have independent confirmation of how many systems actually got hit or what data was actually taken from each one.
The FBI claims are the most serious part, though. If ShinyHunters really got into FBI systems, that's a different scale of problem.
They claim they did. They say they have employee names and medical records. But Reuters couldn't verify it, and the FBI is just saying they're investigating.
Exactly. The group made a public claim. The FBI said it's investigating. Those are two different things. We don't know yet if the claim is true.
So what's the actual risk for the organizations Mandiant identified?
If they haven't patched yet, they're still vulnerable. The attackers have proven they know how to find and exploit this specific hole. The firewall alone isn't enough.
And we don't know if ShinyHunters is the only group exploiting this, or if others have figured it out too. Mandiant is reporting on what they saw, not necessarily the full picture.
El Pulso
- ShinyHunters did not retreat when Oracle issued protective guidance — they studied the gap between organizations that deployed firewall rules and those that never installed the actual patch, then targeted precisely that seam.
- The resumed campaign swept across higher education, healthcare, agriculture, transportation, technology, and government agencies in multiple countries, suggesting opportunistic mass exploitation rather than surgical targeting.
- The group claims to have seized medical and psychiatric records of individuals, and has publicly named FBI employees assigned to sensitive operational units — a brazen disclosure tactic designed to amplify pressure and demonstrate reach.
- The FBI confirmed Wednesday it is actively investigating the breach claims, while Oracle has remained silent, leaving affected organizations in a fog of uncertainty about whether their systems were among those compromised.
- Mandiant's report arrived days after ShinyHunters went public with its claims, exposing the dangerous lag between the moment of intrusion and the moment the security community can sound the alarm.
In the quiet architecture of enterprise software that underpins universities, hospitals, and governments, a known wound has been left open long enough for determined hands to reach inside. ShinyHunters, a hacking collective tracked by Google's Mandiant division, has resumed a systematic campaign exploiting an unpatched Oracle PeopleSoft vulnerability across dozens of organizations in multiple countries — adapting their methods when defenses partially closed, and pressing forward where they did not. The breach claims now extend to FBI employee records and medical files, reminding us that in the digital age, the distance between a software update deferred and a life exposed can be measured in days.
Google's Mandiant cybersecurity division has documented a renewed and escalating campaign by ShinyHunters, a hacking group that has been systematically exploiting a known vulnerability in Oracle PeopleSoft — the enterprise software used by organizations worldwide to manage human resources and critical administrative functions.
The group's first wave struck between late May and early June, focusing on universities. When Oracle published protective guidance, the threat seemed to recede. It did not. ShinyHunters instead refined their approach, identifying a critical distinction: organizations that had deployed web application firewall rules to block the exploit but had not yet installed Oracle's actual security patch remained fully exposed beneath that first layer of defense. The attackers pivoted to target precisely those partially protected systems.
The resumed campaign reached dozens of organizations across multiple countries and sectors — higher education, technology, healthcare, agriculture, transportation, and public administration. The breadth of targets suggests the group was not pursuing a specific objective but scanning broadly for any accessible vulnerable system.
The human cost is concrete. ShinyHunters claims to have obtained medical and psychiatric records, and has disclosed the names of FBI employees working in sensitive units. Reuters could not independently verify the FBI-related claims, but the Bureau confirmed Wednesday that it is actively investigating. Oracle declined to comment.
Mandiant's public report came several days after ShinyHunters made its most provocative claims — a delay that reflects the persistent gap between intrusion and disclosure. For organizations still running unpatched PeopleSoft installations, the situation is unambiguous: partial defenses have proven insufficient, and the vulnerability remains under active exploitation.
Google's Mandiant cybersecurity division has documented a renewed campaign by ShinyHunters, a hacking group, systematically exploiting a known vulnerability in Oracle PeopleSoft software across dozens of organizations worldwide. The group's persistence and tactical adaptation reveal how attackers can circumvent standard defenses even after vendors release patches and security guidance.
The initial wave of attacks occurred between late May and early June, when ShinyHunters targeted universities using the PeopleSoft vulnerability. After Oracle published protective measures and guidance, the threat appeared to recede. But the attackers did not abandon their approach—they refined it. According to Mandiant's analysis, ShinyHunters identified a specific gap in many organizations' defenses: companies that had deployed web application firewall rules to block the exploit but had not yet installed the actual security update from Oracle. This distinction proved critical. The group shifted its targeting strategy to focus on these partially defended systems, effectively sidestepping the first line of defense while the underlying vulnerability remained open.
The scope of the resumed campaign is substantial. Mandiant determined that dozens of systems across multiple countries fell victim to the latest attacks. The affected organizations span a broad range of sectors—higher education, technology companies, healthcare providers, agricultural businesses, transportation firms, and government agencies. PeopleSoft, the enterprise software at the center of these attacks, handles sensitive functions including human resources management and other critical administrative operations. The diversity of targets and sectors suggests the attackers were not pursuing a narrow objective but rather casting a wide net for any accessible system running vulnerable software.
The human consequences of these breaches are concrete and troubling. ShinyHunters has claimed to have obtained medical and psychiatric records belonging to individuals, as well as the names of Federal Bureau of Investigation employees working in sensitive operational units. Reuters was unable to independently verify the group's claims about accessing FBI systems. The FBI, however, acknowledged the threat seriously, stating on Wednesday that it was actively investigating reports of a possible breach. Oracle, the vendor whose software vulnerability enabled these attacks, declined to respond to requests for comment.
The timing of Mandiant's public report—released several days after ShinyHunters made its claims about FBI access—underscores the lag between when attackers strike and when the security community can fully document and disclose what happened. This gap creates a window of uncertainty for affected organizations, many of which may not yet know whether their systems were compromised. The group's willingness to publicly claim access to sensitive FBI data, whether or not those claims are entirely accurate, signals a shift toward more brazen disclosure tactics. For organizations still running unpatched PeopleSoft installations, the message is stark: the vulnerability remains actively exploited, and partial defenses are insufficient. The question now is whether the FBI's investigation will reveal the full scope of what was taken and whether other victims will come forward as the breach details emerge.
Citas Notables
ShinyHunters changed tactics to target organizations with web application firewall rules but without the Oracle security update— Google Mandiant analysis
The FBI said it was actively investigating reports of a possible breach— FBI statement