The ShinyHunters Oracle Campaign Is a Vendor-Risk Wake-Up Call
In June 2026, Oracle disclosed CVE-2026-35273, a critical, unauthenticated remote-code-execution vulnerability in PeopleSoft Enterprise PeopleTools. Before the patch shipped, the extortion group ShinyHunters had already been exploiting it as a zero-day, running data-theft operations against PeopleSoft environments between late May and early June and beginning extortion outreach almost immediately after. Reported victim counts exceed 100 organisations across education, insurance regulation, healthcare, and entertainment.
Why this pattern keeps repeating
This isn't the first time a single flaw in a widely deployed enterprise platform has produced a mass-casualty extortion event, and it won't be the last. The pattern is consistent: a large enterprise resource planning or HR platform, deployed by hundreds of organisations with broadly similar configurations, gets one critical unauthenticated RCE - and an opportunistic group scans the internet for exposed instances faster than defenders can patch.
A practical checklist
- Inventory every internet-facing enterprise platform (ERP, HR, CRM, PeopleSoft, E-Business Suite, and similar) and confirm current patch levels - don't assume IT's mental model of "what's exposed" is current.
- Subscribe to vendor security advisories directly rather than relying on general news coverage; the gap between advisory publication and exploitation is often measured in days.
- Segment and monitor these platforms as if they hold your most sensitive data, because in most organisations they do - HR systems hold employee PII, PeopleSoft-style systems often hold financial and identity data too.
- Build an incident response playbook specifically for "mass exploitation of a platform we run," separate from your generic breach playbook - the timeline pressure is different when you're one of a hundred simultaneous victims and public disclosure may outpace your own detection.
- Ask your own vendors, in writing, whether they run any of the platforms implicated in a given campaign, and what their patch cadence looks like.
The organisations that came through this particular campaign cleanly were, overwhelmingly, the ones that already treated their enterprise platforms as sensitive infrastructure requiring the same rigour as a customer-facing application - not as internal tooling that could wait for the next maintenance window.
Sources
Have a security question of your own?
Talk to a Security Expert →