ShinyHunters Expands PeopleSoft Hacking Spree After Defacing FBI Jobs Site
The extortion group ShinyHunters has expanded its hacking spree to dozens of organizations after defacing the FBI's jobs site just days ago. The group, tracked by Google as UNC6240, is using a zero-day vulnerability in Oracle PeopleSoft to gain remote code execution and plant web shells on targeted systems.
According to Google's Threat Intelligence Group, ShinyHunters has modified its exploit to bypass firewall workarounds that some organizations had implemented after the vulnerability was patched by Oracle in June. The group is targeting the Environment Management Hub endpoint in PeopleSoft, which it also exploited in June.
The affected sectors include higher education, technology, healthcare, agriculture, transportation, and government, with dozens of systems worldwide now having web shells planted on them. ShinyHunters claims to have pulled between 2 and 3 terabytes of data from the FBI's careers portal, including home addresses and family details of current, former, and prospective agents.
The group's interest in PeopleSoft is not new, as it spent a year inside Salesforce last year, stealing OAuth tokens from Salesloft's Drift integration to reach roughly 760 downstream Salesforce customer organizations. The pattern across all of its activity is consistent: find one widely deployed enterprise system, exploit the vulnerability, and then scale the same technique across as many victims as possible.
Oracle's patch has been available since June, but some organizations still didn't patch or assumed a firewall rule was good enough. This highlights the issue of outdated software running HR departments and payroll systems, which are often decades old and patched on a schedule set by IT staff who are stretched thin.