ShinyHunters Launches Fresh Mass-Exploitation Campaign Against PeopleSoft Customers
The notorious hacking group ShinyHunters has launched a fresh mass-exploitation campaign targeting Oracle PeopleSoft customers. The integrated enterprise resource planning (ERP) software suite, used by numerous large enterprises for managing core business functions, is vulnerable to exploitation.
According to Google's warning, the hackers have modified their exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint. This new wave of activity stems from UNC6240 modifying its exploit to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure.
The hackers have been deploying web shells on dozens of systems after bypassing WAF rules using 'P' in the request path containing the string '/PSEMHUB'. The attackers have also established persistence through two complementary, single-line JSP web shells and deployed the SideEye backdoor to steal credentials from browsers and applications.
PeopleSoft customers are advised to apply Oracle's patches for CVE-2026-35273, harden their environments, hunt for potential indicators of compromise (IoCs) and data theft, and prepare for extortion in the event of compromise. The hackers have a well-established pattern of data theft extortion, stealing data and threatening to release it on a data leak site unless the victim pays a ransom.
Affected organizations should prepare for extortion communications and monitor for potential public exposure of stolen data. ShinyHunters' initial PeopleSoft campaign focused on the education sector, but the new wave of attacks has expanded to agriculture, government, healthcare, IT services, technology, and transportation organizations.