ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
The ShinyHunters extortion group exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft to gain unauthorized access to university systems, resulting in data theft and a demand for payment. Mandiant identified UNC6240 as the actor behind the attack, which targeted higher education institutions primarily in the United States, exposing sensitive data including email addresses and personal details. The incident highlights the ongoing threat posed by sophisticated actors and the importance of timely patching and proactive security measures.
The ShinyHunters group successfully leveraged a zero-day vulnerability within Oracle PeopleSoft Enterprise PeopleTools, specifically CVE-2026-35273, to infiltrate university systems. This vulnerability, which allowed remote code execution without requiring login credentials, was exploited between May 27th and June 9th, leaving universities exposed until Oracle published its advisory on June 10th. The attackers targeted systems with the Environment Management Hub (PSEMHUB) reachable from outside, a common configuration for PeopleSoft deployments. The attack resulted in the theft of sensitive data, including email addresses, addresses, phone numbers, passport numbers, ethnicity, and disability information, as revealed by a leaked dataset containing approximately 455,000 unique email addresses. The University of Nottingham was confirmed as a victim, and Mandiant subsequently notified over 100 organizations with vulnerable endpoints, with 68% located in the higher education sector, predominantly in the United States.
