ShinyHunters hackers bypass Oracle security defenses as PeopleSoft attacks spread worldwide

- ShinyHunters has resumed large-scale attacks on vulnerable Oracle PeopleSoft systems worldwide.
- Mandiant said the hackers bypassed firewall defenses where organizations had not installed Oracle’s patch.
- The FBI is investigating after ShinyHunters claimed it accessed sensitive employee and medical data.
ShinyHunters has restarted a broad attack campaign against Oracle PeopleSoft, getting around defenses that organizations added after earlier breaches this summer.
Google’s cybersecurity unit, Mandiant, said Friday that the group is carrying out what it called “mass exploitation” of a PeopleSoft security flaw.
The threat intelligence report came days after ShinyHunters said it had stolen FBI personnel data. Alphabet’s Google (NASDAQ: GOOGL) said the attackers changed their methods after defenders reacted to the first wave.
The previous attacks took place between May 27 and June 9, mostly targeting universities.
According to Mandiant, ShinyHunters changed their strategy and started focusing on those companies that had implemented additional web application firewall rules but had not applied Oracle’s (NYSE: ORCL) patch. This new attack has already reached scores of computers all around the world.
As mentioned by Mandiant, higher education, technology, health care, agriculture, transportation, and government sectors were included among the targeted industries by ShinyHunters, while no names of those organizations were provided.
PeopleSoft is very popular when it comes to managing human resources and other important internal operations, even for those organizations that have considerable security capabilities.
Mandiant says ShinyHunters changed tactics after organizations added firewall defenses
According to Mandiant, the attackers adjusted their tactics once security guidelines were made public after the May and June attacks.
Some companies countered by implementing web application firewall filters to prevent the known method of attack. However, such methods could not protect systems that had not installed Oracle’s patch.
ShinyHunters then targeted those unpatched environments. The group changed how it reached the vulnerable PeopleSoft software and continued exploiting the same underlying weakness. Oracle had already issued a patch for the bug.
In addition, the hacking group’s activities have reached the Federal Bureau of Investigation. According to ShinyHunters, the FBI was hacked using a PeopleSoft loophole. Reuters alleges that the leaked data included names of individuals belonging to specific FBI units, alongside their medical and psychiatric records.
The FBI said Wednesday that it was “aggressively investigating” the reported breach. ShinyHunters has claimed responsibility for several major data breaches, and its FBI claim surfaced only days before Mandiant published the new findings about the wider PeopleSoft campaign.
The new activity came after the first wave and includes organizations from different countries and industries. The Mandiant report concentrated on systems with firewall protection installed without the Oracle patch installed.
Larry Ellison pledges more Oracle shares and drops a planned $7.5 billion stock sale
Separate from the hacking campaign, Oracle disclosed new details about co-founder Larry Ellison’s pledged shares. Larry has put up 67 million more Oracle shares as collateral for personal loans than he had at the same point last year. A proxy filing released Friday showed that the number of pledged shares is 19% higher than in 2025.
Those shares are worth about $9.2 billion based on Oracle’s closing price of $137.10.
Larry is also helping finance a major media acquisition involving his son, David Ellison. David’s company, Paramount Skydance Corp. (NASDAQ: PSKY), is seeking to acquire Warner Bros. Discovery Inc. (NASDAQ: WBD) in a transaction valued at $111 billion.
The Ellison family has committed $47 billion in equity funding for the deal. Roughly $24 billion of that amount is coming from three Middle Eastern sovereign wealth funds.
Larry also reversed a large Oracle stock sale plan this month. On September 12, 2026, he canceled a plan that allowed him to sell as many as 50 million Oracle shares. At the stock’s closing price, that block was worth roughly $7.5 billion. Oracle had disclosed the planned sale in a regulatory filing just one day earlier.
The trading plan had been adopted on June 22, 2026, and was scheduled to expire on October 24. Oracle said no shares were sold under it. The company added that Larry “has no other plans to sell any of his Oracle stock.” It did not give a reason for the reversal.
The cancellation followed Oracle’s fiscal first-quarter report. Revenue rose 30% year over year to $19.3 billion, while adjusted earnings per share reached $1.92. Free cash flow was negative $5.40 billion, compared with the $9.56 billion outflow analysts had expected.
Oracle also raised its revenue backlog to $664 billion. The company continues to spend heavily on AI infrastructure while free cash flow remains negative.
The smartest crypto minds already read our newsletter. Want in? Join them.

Jai Hamid
Jai Hamid has been covering crypto, stock markets, technology, the global economy, and the geopolitical events that affect markets for the past 6 years. She has worked with blockchain-focused publications including AMB Crypto, Coin Edition, and CryptoTale on market analyses, major companies, regulation, and macroeconomic trends. She has attended London School of Journalism and thrice shared crypto market insights on one of Africa’s top TV networks.
















