
ShinyHunters exploited a critical zero-day in Oracle PeopleSoft Enterprise PeopleTools, tracked as CVE-2026-35273, to compromise servers and steal data. Organizations running Oracle PeopleSoft PeopleTools 8.61 or 8.62, or any unsupported earlier version, are at risk of active exploitation by ShinyHunters, a data extortion group now using this vulnerability for initial access.
The vulnerability allows an unauthenticated attacker to execute code on a PeopleSoft server with only network access to its HTTP service, and Oracle disclosed it only after the campaign was already underway.
ShinyHunters has historically relied on social engineering rather than software exploits. They use voice phishing against help desk staff and employees, then abuse single sign-on and OAuth to reach data held in SaaS platforms such as Salesforce and Microsoft 365. In the PeopleSoft campaign, they exploited the vulnerability instead, then moved laterally to other servers within the PeopleSoft deployment. As in their other operations, they exfiltrated sensitive data and threatened to leak it unless the victim paid.
Oracle issued an out-of-band fix for CVE-2026-35273 on June 10, 2026, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog two days later. While the flaw affects PeopleTools 8.61 and 8.62, earlier unsupported versions are likely vulnerable as well. Organizations running an affected version should not wait for a routine patch cycle:
MOXFIVE has responded to multiple ShinyHunters intrusions and recently published a report “ShinyHunters Recovery Playbook: What to Do in the First 48 Hours“ covering how to contain and remediate these compromises before the situation escalates. If your organization ran an exposed PeopleSoft instance during the exploitation window, don’t wait for symptoms to appear.
PeopleSoft holds the payroll, financial, and personal records of an entire organization, which is exactly the data the group seeks. Exploitation predated the patch, so any organization that ran an exposed instance during that window may already be compromised, even after applying the fix.


MOXFIVE provides the clarity and peace of mind needed for attack victims during the incident response process. Our platform approach enables victims of attacks to work with a Technical Advisor who provides the expertise and guidance needed in a time of crisis, and facilitates the delivery of all technical needs required, consistently and efficiently.
Learn More
With experience on the front lines responding to incidents daily, MOXFIVE Technical Advisors have the unique ability to connect the dots between business, information technology, and security objectives to help you quickly identify the gaps and build a more resilient environment.