Data Security ShinyHunters gang targets Oracle PeopleSoft servers in data theft attacks June 10, 2026 Share By SC Staff (Adobe Stock) Oracle PeopleSoft servers are currently being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations. PeopleSoft is an enterprise business software suite used by large organizations to manage various business operations, according to a recent report by Bleeping Computer. The ShinyHunters gang is exploiting a combination of old and zero-day vulnerabilities, referred to as a "gadget chain," to target both cloud and on-premises Oracle PeopleSoft instances. While the success rate varies depending on system configuration, the attackers claim to have compromised data from approximately 300 instances across more than 100 organizations, with a significant number of victims in the education sector. Nottingham University has confirmed a cybersecurity incident, and its data has reportedly been published on the ShinyHunters data leak site. The attackers' initial goal was to breach an FBI portal, but this attempt was unsuccessful. Security researchers have identified exposed directories containing attack tooling, including MeshCentral agents and credential spray scripts, and have shared IP addresses linked to the attacks. Some of these IPs used TLS certificates associated with ShinyHunters. Evidence suggests the attackers create ransom notes on breached servers and attempt to connect to other PeopleSoft systems using common administrative credentials. Organizations running PeopleSoft are advised to analyze logs for suspicious connections and initiate incident response if targeting is detected. Source: Bleeping Computer SC Staff Related Data Security SoFi Hong Kong warns of data breach after third-party vendor compromise SC Staff June 9, 2026 The breach involves a database managed by a third-party vendor used by SoFi Securities (Hong Kong) Limited. Data Security FTC orders Illuminate Education to improve data security after student data breach SC Staff June 8, 2026 The FTC's order stems from allegations that Illuminate failed to implement reasonable security controls, contributing to a December 2021 cyberattack. Data Security New Pink cybercrime group targets corporate data using vishing and cloud theft SC Staff June 8, 2026 Pink avoids traditional malware, instead employing voice phishing (vishing) to trick employees into visiting credential-stealing domains. Related Events Cybercast Beyond the Hype: The Cybersecurity Trends CISOs are Keeping an Eye on in 2026 On-Demand Event Cybercast Beyond the data perimeter: Why next-generation DSPM is the foundation for modern data security On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Block Cipher Checksum Cipher Ciphertext Data Aggregation Data Encryption Standard (DES) Decryption Diffie-Hellman Digital Envelope Digital Signature You can skip this ad in 5 seconds