[Global] Oracle PeopleSoft hacked again despite previous fixes

[Global] Oracle PeopleSoft hacked again despite previous fixes
30 Sep 2026

Google’s security unit has warned that the extortion group ShinyHunters is back inside the Oracle PeopleSoft HR system, HRD reports.

Many large employers rely on Oracle PeopleSoft to run their payroll and personnel records.

This summer, the hackers stole payroll and employee records from universities, carmakers and public bodies. This time, they reportedly infiltrated organisations that believed they had already closed the gap. 

On September 25, Google's security unit Mandiant stated that ShinyHunters had launched a new round of attacks on Oracle PeopleSoft. It confirmed that dozens of systems had been impacted worldwide, in higher education, healthcare, government and other sectors. 

The majority of targets had reportedly responded to the first attacks with a temporary workaround rather than Oracle's fix, and the hackers found a way around it. Mandiant clarified that such workarounds "are not a substitute for patching." 

PeopleSoft's HR and payroll software stores staff bank details, tax records and ID numbers. After the first wave of attacks, Nissan told employees in the US, Canada, Mexico and Brazil that their Social Security numbers and bank details may have been stolen. 

In addition, ShinyHunters claimed it had taken payroll and medical records from the Council of Europe. 

The warning reportedly came days after ShinyHunters claimed it had hacked the FBI's recruitment website and stolen data on agents and job applicants. The FBI says it is "actively and aggressively investigating." 


Source: HRD

(Links via original reporting)

 

Google’s security unit has warned that the extortion group ShinyHunters is back inside the Oracle PeopleSoft HR system, HRD reports.

Many large employers rely on Oracle PeopleSoft to run their payroll and personnel records.

This summer, the hackers stole payroll and employee records from universities, carmakers and public bodies. This time, they reportedly infiltrated organisations that believed they had already closed the gap. 

On September 25, Google's security unit Mandiant stated that ShinyHunters had launched a new round of attacks on Oracle PeopleSoft. It confirmed that dozens of systems had been impacted worldwide, in higher education, healthcare, government and other sectors. 

The majority of targets had reportedly responded to the first attacks with a temporary workaround rather than Oracle's fix, and the hackers found a way around it. Mandiant clarified that such workarounds "are not a substitute for patching." 

PeopleSoft's HR and payroll software stores staff bank details, tax records and ID numbers. After the first wave of attacks, Nissan told employees in the US, Canada, Mexico and Brazil that their Social Security numbers and bank details may have been stolen. 

In addition, ShinyHunters claimed it had taken payroll and medical records from the Council of Europe. 

The warning reportedly came days after ShinyHunters claimed it had hacked the FBI's recruitment website and stolen data on agents and job applicants. The FBI says it is "actively and aggressively investigating." 


Source: HRD

(Links via original reporting)

 

Leave a Reply

All blog comments are checked prior to publishing