# Oracle PeopleSoft Zero-Day Weaponized Against Universities: 455,000+ Exposed in ShinyHunters Campaign
A critical remote code execution vulnerability in Oracle PeopleSoft was exploited as a zero-day by the ShinyHunters extortion crew, compromising over 100 organizations and exposing more than 455,000 individuals' personal data. The attack campaign, attributed by Google Mandiant to the group tracked as UNC6240, ran for nearly two weeks before Oracle published a security advisory on June 10, 2026. Universities bore the brunt of the targeting, with 68 percent of affected organizations operating in higher education.
## The Threat
CVE-2026-35273 is a network-accessible remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools with a CVSS severity rating of 9.8 out of 10—placing it in the highest criticality tier. The flaw requires no authentication, no user interaction, and only network access over HTTP to achieve complete server compromise.
The vulnerability resides in the PeopleSoft Environment Management Hub (PSEMHUB), specifically within the Updates Environment Management component. Organizations that exposed PSEMHUB endpoints to external networks—a common misconfiguration in enterprise deployments—became vulnerable to immediate exploitation.
Confirmed victims include:
Google Mandiant's Cyber Threat Analysis Group (CTAG) confirmed active exploitation in the wild, and analysis of exposed attacker infrastructure reveals this was not a targeted campaign but opportunistic scanning for vulnerable instances across the internet.
## Background and Context
ShinyHunters, also tracked as UNC6240 by Mandiant, has operated as an extortion-focused threat group for several years. The crew combines theft with extortion—stealing data and then threatening to publish it unless victims pay a ransom. The group maintains a public leak site where stolen data is posted, creating reputational and regulatory pressure on victims.
The exploitation campaign ran from May 27 to June 9, 2026—a 14-day window during which the vulnerability remained unknown to Oracle and unpatched across the internet. This zero-day window allowed attackers to operate with complete operational freedom. Oracle's security advisory, published June 10, came only *after* active exploitation was already widespread.
Why universities? Higher education institutions historically run Oracle PeopleSoft for student information systems, human resources, and financial management. Many operate with legacy IT infrastructure and mixed internet accessibility—a common recipe for exposed management interfaces. The sector is also attractive to extortion operators because universities handle sensitive personal data (names, addresses, contact information, and for international students, passport details) and are often resource-constrained in security operations, making them more likely to negotiate ransom payments.
## Technical Details
### The Vulnerability
The flaw exists in the Environment Management Hub component, which administrators use to manage multi-server PeopleSoft deployments. It allows unauthenticated, network-accessible code execution. An attacker needs only to craft a malicious HTTP request to a vulnerable endpoint to execute arbitrary commands on the underlying server.
Affected versions:
The vulnerability was reported by researchers from TrendAI Zero Day Initiative and TrendAI Research.
### Attack Infrastructure and Tactics
Researcher @nahamike01 discovered open directories on attackers' staging servers, which Mandiant subsequently triaged. The exposed infrastructure revealed the group's operational playbook:
Five Python SimpleHTTP servers (port 8888) hosted:
.bash_history files documenting commands executed during intrusionsThe lateral movement tool ([victim]_fanout.sh) employed brute-force SSH attacks against internal hosts, using a hardcoded list of common credentials. Upon successful compromise, it deployed a marker file: README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT into PeopleSoft directories.
Command history evidence showed:
zstd### Data Exposed
Have I Been Pwned registered approximately 455,000 unique email addresses in the leaked dataset. The exposed records include:
| Data Type | Impact |
|-----------|--------|
| Names & Addresses | Identity fraud risk, physical security risk |
| Phone Numbers | Targeted phishing and social engineering |
| Passport Numbers | Identity theft, fraud, travel document abuse |
| Ethnicity & Disability Data | Privacy violation, potential discrimination, GDPR/accessibility law violations |
| Student Status | Targeting of potentially vulnerable populations |
University of Nottingham confirmed the breach and notified affected individuals. The diversity of exposed personal identifiers creates compounding risk—attackers can use this data for credential stuffing, social engineering, and coordinated fraud campaigns.
## Implications
### For Higher Education
Universities are now operating in a post-breach environment where 455,000+ current students and alumni know their personal data is in criminals' hands. This creates:
### For Oracle Customers Generally
The 14-day zero-day window demonstrates a critical supply chain risk: enterprises depending on Oracle PeopleSoft had no mitigation available during active exploitation. Patches were promised but availability unclear at the time of advisory publication.
Organizations that:
## Recommendations
### Immediate Actions (Next 24 Hours)
1. Identify vulnerable endpoints:
- Audit all instances of PeopleTools 8.61/8.62
- Verify whether PSEMHUB is externally accessible
- Search for /PSEMHUB/hub and /PSIGW/HttpListeningConnector in firewall/WAF logs
2. Block external access:
- Disable the Environment Management Hub service on multi-server deployments, OR
- Remove the PSEMHUB application entirely on single-server systems, OR
- Implement network-level blocking: restrict /PSEMHUB/* and /PSIGW/HttpListeningConnector to internal networks only
- Note: These restrictions do not break legitimate user sessions
3. Activate incident response:
- Organizations with IP addresses matching vulnerable endpoints have been notified by Mandiant
- Assume compromise if your institution was contacted
### Short-Term Investigation (Next 48-72 Hours)
Hunt for compromise indicators:
/PSEMHUB/hub or /PSIGW/HttpListeningConnectorPSEMHUB.war directory for webshellslogs, persistantstorage, or scratchpad folders under PSEMHUB paths.xml files under the web document root### Long-Term Controls
---
## HackWire Analysis
This incident is a masterclass in modern extortion-driven compromises—and a warning about the blind spots in enterprise security.
The zero-day window is the story here. For 14 days, every exposed PeopleSoft instance was a ticking bomb. No patch existed. No workaround was published. Firewalls and WAFs could not protect against a vulnerability they didn't know about. This is supply chain risk in its most naked form: enterprises followed every best practice and *still* got compromised because the vulnerability simply didn't exist in any threat intelligence feed or advisory.
ShinyHunters' operational discipline is also worth noting. They didn't run a surgical, targeted campaign—they scanned the internet for vulnerable instances, exploited them opportunistically, and extracted data at scale. This is the commoditization of enterprise breaches. The group didn't need to crack security; they found something Oracle left unlocked.
The targeting of higher education is not coincidental. Universities are high-value targets for extortion because they operate massive personal data repositories (student records contain addresses, phone numbers, and often passport data for international students), and they're organizationally pressure-sensitive—public breaches damage institutional reputation and enrollment. Plus, many universities operate legacy infrastructure with mixed access controls: systems that are 10+ years old, running on outdated PeopleTools versions, with administrative interfaces that were never meant to be internet-facing but gradually became so through network expansion and vendor remote access.
The exposed attacker infrastructure tells us the group expected *no pushback*. They left Python HTTP servers running with command history and agent binaries sitting in open directories. This is arrogance born of success—they've operated with impunity because extortion is harder to prosecute than pure theft, and victim institutions often pay quietly to avoid publicity.
For defenders: If you run PeopleSoft, this is a reset moment. Assume the attacker is still there if you were contacted by Mandiant. Lateral movement scripts have likely spread beyond the initial compromise. The real breach investigation begins after you block external access and patch. And if you weren't contacted—count yourself lucky, not safe. Scan your own logs before waiting for vendor notifications.
For the broader industry, this is a reminder that zero-days are not rare unicorns—they're inevitable, and your security posture must assume you will be hit by something you didn't know existed. That means network segmentation, aggressive log monitoring, and the ability to respond in hours, not weeks.
— HackWire Editorial
---
## Related Coverage