ShinyHunters has renewed a campaign exploiting a vulnerability in Oracle’s PeopleSoft enterprise software, targeting organizations that failed to install a security update after earlier attacks, according to Google’s cybersecurity unit Mandiant.
Mandiant said on Friday that the hacking group had launched a new wave of what it described as “mass exploitation” after adapting its techniques to bypass defenses introduced following attacks earlier this year.
The development raises fresh concerns for organizations that use PeopleSoft for human resources and other critical business functions, particularly as attackers demonstrate that defensive measures can become ineffective when vulnerabilities remain unpatched.
Register for the next Tekedia Mini-MBA.
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
Mandiant said ShinyHunters exploited a flaw in PeopleSoft between May 27 and June 9, with the initial campaign mainly affecting universities. The hackers have now returned with modified techniques aimed at organizations that followed some of the defensive guidance issued after those attacks but failed to install Oracle’s security update for the vulnerability.
ShinyHunters had earlier this month claimed it hijacked rival cybercrime group cl0p’s dark-web site.
The latest campaign has affected dozens of systems globally, Mandiant said, spanning higher education, technology, healthcare, agriculture, transportation and government.
The attacks illustrate a familiar problem in enterprise cybersecurity: deploying additional security controls around a vulnerable application can reduce exposure but may not eliminate the underlying risk. Organizations that implemented web application firewall rules without applying Oracle’s patch remained vulnerable to attackers who adapted their methods.
Mandiant did not identify the affected organizations.
The renewed campaign also comes days after ShinyHunters claimed it had stolen data belonging to FBI personnel, adding a potentially significant government dimension to the hacking group’s recent activity.
The FBI said on Wednesday that it was “aggressively investigating” the reported breach.
Reuters reported that ShinyHunters had exposed the names of personnel working in sensitive FBI units and obtained medical and psychiatric records. The group has claimed that its access to FBI data was also connected to the PeopleSoft vulnerability.
Mandiant’s findings show why the distinction between mitigating a vulnerability and actually patching it can be important.
Following the May and June attacks, security guidance encouraged organizations to deploy web application firewall rules intended to block malicious activity targeting the PeopleSoft flaw. Mandiant said ShinyHunters subsequently modified its attack methods to get around those protections.
Organizations that had installed the Oracle update were no longer dependent solely on those perimeter defenses for protection against the vulnerability.
The latest campaign therefore appears to have focused on a gap between organizations that had recognized the threat and those that had completed the underlying remediation.
That creates a particularly difficult situation for large institutions. Enterprise software such as PeopleSoft can sit deep inside corporate and government infrastructure and support functions including human resources, payroll and employee administration. Applying patches can require testing, scheduling and coordination across large technology environments, meaning that vulnerabilities can remain exposed after a security update becomes available.
The result is a race between defenders attempting to complete remediation and attackers looking for organizations that have not yet done so.
Mandiant’s identification of victims across multiple industries suggests that the campaign is not confined to a particular sector.
Higher education organizations were among the main targets of the earlier attacks, but the latest activity has expanded across technology, healthcare, agriculture, transportation, and government. That broad targeting increases the potential consequences because PeopleSoft installations can contain substantial amounts of employee and organizational information.
The reported FBI incident adds another layer to the concern, although the connection remains based on ShinyHunters’ claim rather than independently verified evidence.
The PeopleSoft campaign highlights a broader cybersecurity problem for large organizations: widely deployed enterprise applications can become attractive targets because a single vulnerability can provide access to many potential victims.
Attackers do not necessarily need to compromise an organization through sophisticated zero-day exploits. A publicly disclosed vulnerability can remain valuable for months when patches have not been applied across every affected system.
The ShinyHunters campaign also demonstrates how attackers can adjust after security teams introduce new barriers. A web application firewall can block known malicious patterns, but if the underlying software remains vulnerable, attackers can search for ways around those controls.
For organizations running PeopleSoft, the latest Mandiant warning therefore increases the importance of determining whether Oracle’s security update has been applied rather than relying exclusively on network-level protections.
The timing also matters for the cybersecurity industry because ShinyHunters has established itself as a prominent data-breach group. Its claimed involvement in major incidents means that renewed exploitation of an enterprise software vulnerability can attract substantial attention from organizations that might otherwise regard the original attacks as isolated incidents.
Mandiant’s warning provides a more concrete indication of the threat. It says the campaign is active, has affected dozens of systems across several industries, and has evolved specifically to bypass defenses deployed after the earlier attacks.
For organizations that continue to operate vulnerable PeopleSoft systems, the distinction between having defensive rules in place and having fully remediated the vulnerability could prove consequential.



