Over 100 organizations
The financially motivated threat group ShinyHunters has been identified as the actor behind a widespread campaign exploiting a zero-day vulnerability in Oracle PeopleSoft. The critical flaw, CVE-2026-35273, is an unauthenticated remote code execution (RCE) vulnerability with a CVSS score of 9.8. Between late May and early June 2026, the group used this exploit to breach over 100 organizations globally before a patch was available. A joint report from Mandiant and Google's Threat Intelligence Group revealed that the campaign disproportionately targeted the higher education sector, which accounted for 68% of victims, primarily in the United States. The University of Nottingham has been publicly named as a victim. In response to active exploitation, CISA has added the CVE to its Known Exploited Vulnerabilities (KEV) catalog, demanding federal agencies remediate by June 15, 2026.
The core of the attack is the exploitation of CVE-2026-35273. This vulnerability in Oracle PeopleSoft Enterprise PeopleTools (versions 8.61 and 8.62) allows an unauthenticated attacker with network access to the system to execute arbitrary code, leading to a complete takeover.
T1190 - Exploit Public-Facing Application: ShinyHunters used the zero-day exploit against internet-facing Oracle PeopleSoft instances to gain initial access.T1071.001 - Web Protocols: The attackers used customized MeshCentral agents for command and control (C2), communicating over standard web protocols to disguise their traffic.T1105 - Ingress Tool Transfer: After gaining access, the attackers downloaded their post-exploitation toolkits, including the MeshCentral agents.T1567 - Exfiltration Over Web Service: The group exfiltrated large volumes of data (e.g., 40 GB from the University of Nottingham) to be used for extortion.T1048 - Exfiltration Over Alternative Protocol: The use of MeshCentral, a remote management tool, for C2 and data staging can be considered an alternative protocol for exfiltration.Mandiant's analysis noted the use of customized MeshCentral agents, an open-source remote management tool. By disguising these agents as legitimate cloud endpoints, ShinyHunters could maintain persistence and execute commands stealthily.
The impact on affected organizations, particularly universities, is severe. PeopleSoft systems often serve as the central hub for student information systems (SIS), human resources (HR), and financial data. A successful breach can lead to:
No specific Indicators of Compromise (IPs, domains, hashes) were provided in the source articles.
Security teams may want to hunt for the following patterns to identify potentially compromised PeopleSoft systems:
process_namepsft.exe, psappsrv.exeprocess_nameMeshCentral.exe, MeshAgent.exenetwork_traffic_pattern*.meshcentral.comlog_sourcefile_pathC:\Program Files\PeopleSoft\University of Nottingham confirms 454,600 student records, including passport numbers, stolen by ShinyHunters via Oracle PeopleSoft zero-day.
The University of Nottingham has confirmed a data breach affecting approximately 454,600 current and former students. The ShinyHunters group exploited CVE-2026-35273 in Oracle PeopleSoft to steal highly sensitive personal information, including passport numbers, contact details, enrollment information, and fee payment records. This update provides concrete details on the scale and sensitivity of the data compromised for a previously identified victim, underscoring the severe impact of the ongoing campaign.
University of Nottingham breach details confirmed: 455,000 individuals affected, 40GB data including passport numbers stolen. Regulatory bodies notified.
New reports confirm the University of Nottingham breach by ShinyHunters impacted approximately 455,000 current and former students. Attackers exfiltrated 40 GB of sensitive data, including names, addresses, and critically, passport numbers. The university has notified affected individuals and reported the incident to the UK's ICO and Action Fraud. This update provides specific impact metrics for a previously identified victim, highlighting the severe consequences of the Oracle PeopleSoft zero-day exploitation. Additionally, new hunting hints for the /PSEMHUB/ URL pattern have been identified.
ShinyHunters begins exploiting the Oracle PeopleSoft zero-day.
Data stolen from victims is posted on ShinyHunters' leak site. The initial attack campaign ends.
Oracle releases a security alert about the vulnerability.
CISA adds CVE-2026-35273 to its KEV catalog.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.