Google says the extortion gang behind the FBI jobs site defacement has widened its Oracle PeopleSoft campaign to dozens of organizations, using the same zero-day it first exploited in June.
You run payroll, benefits, and HR records through PeopleSoft, and there’s a decent chance your organization is on a list Google’s Threat Intelligence Group is currently working through. On Friday, September 25, Google Cloud’s threat intelligence team reported that ShinyHunters, the extortion group it tracks as UNC6240, has renewed a mass-exploitation campaign against Oracle PeopleSoft. It’s hitting systems across higher education, technology, healthcare, agriculture, transportation, and government, according to Google’s own blog post on the findings.
The vulnerability is CVE-2026-35273, a critical, unauthenticated remote code execution flaw in PeopleSoft Enterprise PeopleTools with a CVSS score of 9.8. Oracle patched it in an out-of-band alert on June 10, after Google identified active exploitation between May 27 and June 9 that hit more than 100 organizations, roughly 68% of them universities, according to Tenable’s analysis of the June patch cycle. Some organizations didn’t patch. They tweaked firewall rules instead, and that’s exactly the gap ShinyHunters just walked back through.
Google says the group is now modifying its exploit specifically to get past those firewall workarounds, going after the same Environment Management Hub endpoint, known as PSEMHUB, that it targeted in June. Dozens of systems worldwide now have web shells planted on them. The attackers are pulling internal PeopleSoft configuration files and WebLogic server settings to map out networks: that’s according to Google’s report. It’s the same playbook that turned a single point of entry into a sprawling breach across hundreds of Salesforce customers last year.
Three days before Google’s report, on Monday, September 22, ShinyHunters defaced the FBI’s jobs site, FBIjobs.gov, replacing agency imagery with the Pokémon character that’s become the group’s calling card. A spokesperson for the group told reporters, and 404 Media confirmed with sample records, that the entry point was the same Oracle PeopleSoft zero-day, exploited on the FBI’s careers portal to gain remote code execution. From there, ShinyHunters claims it moved laterally onto FBI-managed servers hosted on AWS GovCloud. It says it pulled between 2 and 3 terabytes of data on current, former, and prospective agents, including home addresses and family details, according to reporting from TechCrunch and The Record.
That’s not a coincidence sitting next to the Google report. It’s the same tool used twice in one month, first as a scalpel against a single federal target, then as a blunt instrument against dozens of organizations that never got around to patching. The FBI said it’s investigating. It hasn’t confirmed the scope of what ShinyHunters claims to hold.
PeopleSoft breaches are not abstract. The platform runs payroll, benefits enrollment, and HR case management for a huge share of large employers and government bodies. A successful intrusion routinely exposes Social Security numbers, salary data, direct deposit details, and performance records: the exact data set ShinyHunters is threatening to leak from the FBI. When Google says the September wave hit sectors as different as agriculture and transportation, it’s really saying the exposure isn’t limited to any one industry’s customers. It’s whoever runs this specific enterprise software and didn’t patch fast enough.
This is the same group that just spent a year inside Salesforce
ShinyHunters didn’t appear out of nowhere for this. The group sometimes operates in coordination with actors tracked as Scattered Spider and Lapsus$. It spent the back half of 2025 and much of 2026 running a different but related campaign: stealing OAuth tokens from Salesloft’s Drift integration to reach roughly 760 downstream Salesforce customer organizations, a breach Salesloft eventually traced back to a compromised GitHub account from as early as March 2025. Microsoft mapped three separate Salesforce attack paths tied to a year of the group’s activity, according to reporting from The Hacker News in July. By March 2026, the group had pivoted again, this time extorting organizations running public-facing Salesforce Experience Cloud portals.
The pattern across all of it is consistent: find one widely deployed enterprise system, find the organizations too slow to patch or too confident in a stopgap fix, then scale the same technique across as many victims as possible before the industry catches up. PeopleSoft is just the current target. Rapid7 flagged active exploitation of CVE-2026-35273 back in June, months before this week’s escalation, and the vulnerability sat there anyway.
There’s a broader point here that’s easy to miss while everyone’s attention is on AI infrastructure spending. Companies are pouring capital into frontier models and data center buildouts. But the software actually running their HR departments and payroll systems is often decades old, patched on a schedule set by IT staff who are stretched thin. PeopleSoft has existed since the 1980s. It’s not going away, and neither, it seems, is ShinyHunters’ interest in it. Oracle’s patch has been available since June. The organizations still exposed in September are the ones that assumed a firewall rule was good enough.
Also read: The AI industry has spent about $1.4 trillion and earned back roughly half • Startup DaVoice sues Perplexity AI over stolen wake word technology • A 13 year old hacked Microsoft Teams and Microsoft rewrote its rules for him
This article is posted in AI News, check it out for more related stories.
Almost there. Sign in and your reply posts straight away.
Click Here For The Original Source.
