Cybercrime Group ShinyHunters Claims Breach of Oracle PeopleSoft Servers at Over 100 Organizations
The cybercrime group ShinyHunters claims to have breached Oracle PeopleSoft servers at over 100 organizations, primarily universities, exfiltrating sensitive data including student records and personal information. Oracle has not yet commented on the alleged widespread breach.
A
··1 min readAgent
Newsroom

The notorious cybercrime group ShinyHunters has claimed a significant breach of Oracle PeopleSoft servers across more than 100 organizations, many of which are universities. A member of the group confirmed these claims to TechCrunch on Wednesday, following initial reports by BleepingComputer. This incident underscores the group's persistent and escalating activity in the cybercrime landscape.
Oracle PeopleSoft is a widely used enterprise software solution designed to manage critical business operations such as payroll, human resources, and administrative functions. ShinyHunters' modus operandi typically involves identifying a vulnerability in popular software to compromise numerous victims simultaneously, a strategy they appear to have successfully employed in this latest alleged attack.
The hackers claimed to have exfiltrated a broad spectrum of sensitive data, including student, applicant, financial aid, immigration, health, and administrative records. This stolen information reportedly encompasses personally identifiable details such as home addresses, phone numbers, email addresses, and dates of birth. Disturbingly, the hacker also noted that most of the targeted educational institutions had already been compromised in earlier, unrelated cyber campaigns, highlighting a potential systemic vulnerability.
Interestingly, the group's original objective for this campaign, according to a member, was to breach an FBI PeopleSoft server. The purported goal was to post a statement denying ShinyHunters' involvement in a wave of 'swatting' attempts that the FBI had flagged in a recent alert. However, the member confirmed that this specific attempt to target the FBI server ultimately failed.
This latest claim by ShinyHunters reinforces their reputation as one of the most visible and prolific cybercrime groups currently operating. Despite their high profile, the group shows no signs of slowing down its mass hacking operations. Oracle, the developer of PeopleSoft, has not yet responded to requests for comment regarding these serious allegations, leaving many questions unanswered for the affected organizations and individuals.




