A flaw affecting Oracle's widely-used PeopleSoft software has become the focus of a renewed attack wave by ShinyHunters, the hacking collective behind last week's breach of an FBI recruitment portal. Google's Mandiant security division released analysis on Friday detailing how the group has adapted its tactics to circumvent published defences.

The vulnerability in question, tracked as CVE-2026-35273, surfaced publicly in June and affects PeopleSoft systems deployed across government bodies, educational institutions and healthcare organisations for functions including invoice processing, project management and personnel administration. Mandiant first documented ShinyHunters weaponising the flaw as a zero-day between 27 May and 9 June against academic targets. Oracle issued a patch on 10 June, and Mandiant subsequently outlined mitigation strategies for those unable to deploy the fix immediately.

The group's latest campaign shows a troubling shift in strategy. According to Mandiant, "ShinyHunters had restarted its exploitation of the bug and adapted to published defensive guidance, targeting organizations that implemented [workarounds] but did not patch the vulnerability."

The scope of the fresh assault is extensive. Mandiant stated that "our analysis indicates that the threat actor expanded their targeting in this recent campaign, deploying web shells on dozens of systems globally, spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government."

ShinyHunters claimed responsibility for the FBI breach last week, which involved defacing the agency's jobs portal and allegedly extracting extensive records on FBI operations and personnel. An internal memo to FBI staff, reviewed by the New York Times, indicated senior leadership believes the attackers also obtained personal information belonging to all FBI employees.

The group publicly stated it had gained entry through an Oracle PeopleSoft vulnerability, triggering urgent questions about whether they had discovered a previously unknown flaw or were leveraging an existing one. Mandiant's investigation of compromised systems revealed that attackers successfully moved laterally from the initial vulnerability to achieve full operating system control or extract sensitive configuration details, database credentials and application records.

Oracle's own website identifies dozens of major PeopleSoft deployments among U.S. and international government agencies, healthcare providers and universities. Mandiant has advised all organisations to examine database activity logs for suspicious queries targeting human resources, payroll and student information tables.

The group's modus operandi follows a consistent pattern. Mandiant noted that "[ShinyHunters] has a well-established pattern of data theft extortion, that is, stealing data and threatening to release it on a data leak site unless the victim pays a ransom. Affected organizations should prepare for extortion communications and monitor for potential public exposure of stolen data."

ShinyHunters has claimed responsibility for numerous high-profile breaches in recent months and has drawn sustained FBI attention for nearly a year following attacks on major corporations including Ticketmaster, AT&T, McGraw Hill, Carnival Cruise Line and 7-Eleven. The FBI operation represents an escalation, with the group distributing 5,000-record samples of stolen data to multiple news organisations including Reuters, 404 Media and the BBC. These samples contained medical records, intelligence on classified FBI units and detailed agent information.

Progress in disrupting the group came on Monday when Dutch authorities arrested a 24-year-old suspected ShinyHunters member in Amsterdam. According to cybersecurity journalist Brian Krebs, the individual held a senior position within the operation and was engaged in a power dispute with another hacker based in Jordan over leadership of the criminal enterprise.