Singapore · Wednesday, September 30, 2026
asianomistAsia’s economy, daily.
Tech & Semiconductors

Google's Mandiant flags renewed ShinyHunters attacks on Oracle PeopleSoft

Google's cybersecurity unit, Mandiant, reported the hacking group ShinyHunters bypassed previous security measures to exploit a flaw in Oracle's PeopleSoft, affecting dozens of global systems.

By Asianomist DeskPublished 27 September 20261 min read
Photo: Ryan Quintal / Unsplash

Renewed Exploitation of PeopleSoft Vulnerability

Google's cybersecurity arm, Mandiant, announced on Friday (September 25) that the hacking group ShinyHunters has recommenced widespread exploitation of a vulnerability within Oracle's PeopleSoft software. This follows earlier attacks during the summer, where the group reportedly circumvented existing defensive measures.

Mandiant's threat intelligence report detailed the renewed activity, raising concerns for organisations utilising PeopleSoft for critical functions like human resources.

Evolving Attack Tactics and Global Scope

The Google unit stated that ShinyHunters initially exploited the PeopleSoft bug in attacks between May 27 and June 9, primarily impacting universities. Subsequently, the hackers adjusted their tactics, targeting entities that had implemented web application firewall rules but failed to apply an essential update issued by Oracle to patch the vulnerability.

The latest wave of attacks has affected dozens of systems worldwide, spanning diverse sectors including higher education, technology, healthcare, agriculture, transportation, and government.

FBI Data Breach Claim and Oracle's Silence

ShinyHunters has publicly claimed responsibility for accessing personnel data from the US Federal Bureau of Investigation (FBI), reportedly through the PeopleSoft vulnerability. Previous reports indicated this breach exposed names of staff in sensitive FBI units, alongside medical and psychiatric records.

The FBI confirmed on Wednesday (September 23) that it is "aggressively investigating" the reported incident. Oracle, the software provider, has not yet responded to requests for comment regarding the security flaw or the ongoing exploitation.

Operational Risks for Asian Entities

This renewed exploitation of Oracle's PeopleSoft vulnerability presents a significant operational risk for Asian companies and public sector entities relying on the software for human resources and enterprise resource planning (ERP).

Organisations in sectors such as higher education, healthcare, and government across Asia must prioritise applying Oracle's security patches and review their existing web application firewall configurations.

Failure to implement these updates could lead to costly data breaches, operational disruptions, and potential regulatory penalties, affecting financial stability and customer trust.

This article is journalism, not investment advice; consult a licensed professional before making financial decisions. Market data is indicative, may be delayed, and should be verified with your broker or exchange before use.

Comments.

Comments are moderated. We remove what is unlawful, abusive or off-topic, and and you remain responsible for what you post.

Reader comments open soon. Until then, corrections and responses go to our newsroom, and we publish what we get wrong on Corrections.