ShinyHunters exploits Oracle PeopleSoft zero-day to breach 100+ organizations, including University of Nottingham
The cybercriminal group ShinyHunters exploited a critical zero-day vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software to breach more than 100 organizations, stealing gigabytes of sensitive data including student records. Oracle issued a security advisory on June 10, 2026 — after the attacks had already occurred between May 27 and June 9 — rating the flaw a CVSS 9.8 and confirming it allows remote code execution without authentication. The campaign disproportionately targeted higher education institutions, with roughly 68% of affected organizations being universities or colleges, and has prompted urgent warnings from Google's Mandiant unit for all PeopleSoft customers to patch immediately.
ShinyHunters, a prolific extortion-focused hacking group active since at least 2019, exploited a previously unknown vulnerability in Oracle PeopleSoft — an enterprise resource planning platform widely used for HR, finance, and payroll — to compromise more than 100 organizations globally, most of them in the United States. Because the attacks occurred between May 27 and June 9, 2026, before Oracle published its security advisory on June 10, the flaw was used as a zero-day, meaning no patch existed at the time of exploitation. Google's Mandiant unit tracked the campaign, notified over 100 organizations with potentially vulnerable endpoints, and confirmed that stolen data from some victims was published on ShinyHunters' dark-web data leak site, with one victim alone losing 48 GB of data. Attackers deployed customized MeshCentral agents disguised as legitimate cloud endpoints to run administrative commands, performed reconnaissance on PeopleSoft configurations, and exfiltrated compressed data to an IP address hosting ShinyHunters' leak site. The University of Nottingham — a prominent Russell Group institution — was among the confirmed victims, with Have I Been Pwned logging approximately 455,000 exposed email addresses alongside names, addresses, phone numbers, ethnicities, disabilities, passport numbers, and academic and financial records. ShinyHunters has demanded ransoms from victims, threatening to release stolen data if payment is not made, and Oracle is urging all PeopleSoft users running versions 8.61 and 8.62 to apply the available patch immediately and audit logs for suspicious activity from late May through early June.
What's missing
The total number of organizations that experienced confirmed data theft — as opposed to those merely notified of potential exposure — has not been precisely disclosed. The full scope of financial or reputational harm to affected institutions has not yet been assessed.
How coverage differed
Coverage was broadly consistent across outlets, though The Register focused primarily on the University of Nottingham breach and its timing amid a staff industrial dispute, while TechCrunch, Ars Technica, Channel NewsAsia, and TechRadar centered their reporting on the broader Oracle PeopleSoft zero-day campaign and its systemic implications for higher education globally.
What different sources said
- Channel NewsAsiaCenter
Google says ShinyHunters hackers targeting education sector via Oracle exploit
- The RegisterCenter
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
- TechCrunchCenter
Oracle warns of security bug that hackers abused to breach 100+ companies
- Ars TechnicaCenter
PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data
- TechRadarCenter
Oracle warns customers of critical PeopleSoft attack after hundreds of servers hacked by apparent ShinyHunters data theft attacks
Related

Samsung Galaxy S25 and S25 FE See Significant Price Cuts
Samsung's Galaxy S25 and Galaxy S25 FE smartphones are currently available at notably reduced prices, with the S25 FE dropping $201 (33%) to $449 on Woot for a limited time. The price reductions come amid a competitive smartphone market and ahead of anticipated future Samsung releases. The discounts make previously premium-priced devices more accessible to budget-conscious consumers.

Anthropic Disables Fable 5 and Mythos 5 AI Models Globally After US Government Export Control Order
Anthropic has suspended all public access to its two most advanced AI models, Fable 5 and Mythos 5, after the US Commerce Department issued an export control directive ordering the company to block foreign nationals from accessing them on national security grounds. The order came just three days after Fable 5's public launch and reportedly stems from government concerns about a potential jailbreak that could enable the models to assist with cyberattacks, though Anthropic says it received only verbal evidence of a narrow, non-universal vulnerability. The shutdown affects all customers globally — including enterprise users and Anthropic employees — and marks a significant escalation of US efforts to restrict foreign access to advanced AI models themselves, rather than just the chips that power them.

Xbox Free Play Days Offers Three Games Free to Play June 11–14
Microsoft's Xbox Free Play Days program is offering Hell Let Loose, State of Decay 2: Juggernaut Edition, and Blasphemous 2 at no cost from June 11 to June 14. Hell Let Loose requires an Xbox Game Pass Ultimate, Premium, or Essential membership, while State of Decay 2 and Blasphemous 2 (via a five-hour timed trial) are accessible to all Xbox console owners. Players who wish to keep any of the games can purchase them at a limited-time discount and retain any achievements earned during the free period.