Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
The ShinyHunters extortion gang is targeting Oracle PeopleSoft servers in ongoing data theft attacks, having already compromised over 300 instances across more than 100 organizations. They are exploiting a chain of old and zero-day vulnerabilities, primarily focusing on the education sector, and have published stolen data from Nottingham University. Organizations running PeopleSoft should immediately investigate potential compromise and take preventative measures.
The attacks, as reported by BleepingComputer, involve the ShinyHunters gang leveraging a 'gadget chain' of vulnerabilities to gain access to Oracle PeopleSoft environments. The gang’s initial stated goal was to breach an FBI portal running PeopleSoft, but this attempt was unsuccessful. The group is actively targeting organizations using PeopleSoft for managing business operations like HR, finance, and supply chain, with a significant number of victims already identified within the education sector, including Nottingham University, where data has been publicly released. The gang’s tactics include using staging materials like MeshCentral agents and a defacement/credential spray script, alongside a shell script designed to create ransom notes and exploit common administrative accounts.