September 26, 2026: A threat group tracked by Google as UNC6240 and widely associated with ShinyHunters has expanded attacks against Oracle PeopleSoft systems, according to Google’s Mandiant threat-intelligence team. The renewed campaign is exploiting organisations that remain exposed to a critical remote-code-execution vulnerability, even after Oracle issued a security advisory and defenders circulated mitigation guidance.
Reuters reported that dozens of systems around the world had been compromised in the latest activity. The claim that the group breached the US Federal Bureau of Investigation remains uncorroborated, and should not be presented as established fact. The verified concern is broader: vulnerable PeopleSoft infrastructure is still reachable and attackers have adapted their methods where organisations relied on partial defences instead of fully remediating the flaw.
What vulnerability is being exploited?
Google Threat Intelligence Group and Mandiant linked the campaign to CVE-2026-35273, a critical vulnerability in the Environment Management component of Oracle PeopleSoft. Google assigned the issue a CVSS severity score of 9.8 and said it can enable remote code execution. Its investigators observed exploitation from May 27 to June 9, before Oracle’s June 10 advisory, making the early activity a zero-day campaign.
The attackers targeted PeopleSoft Environment Management Hub endpoints. Once access was gained, investigators observed tools and infrastructure used to establish command-and-control channels, maintain access and support extortion. Universities were heavily represented in the first wave, but the technology is also used by public bodies and large enterprises for human resources, finance and administration.
The current warning shows why security teams cannot treat the June disclosure as a closed incident. Attackers revisit widely deployed enterprise software because patching is uneven, internet-facing systems are easy to scan and sensitive administrative databases can support both theft and extortion.
Why firewall-only protection can fail
Mandiant said the campaign evolved after defenders published firewall guidance. A firewall rule can reduce exposure, but it is not a substitute for installing the vendor’s security update, validating configuration and checking for signs of earlier compromise. Rules can be incomplete, deployed on only part of an environment or bypassed through an allowed path.
Organisations should first inventory every PeopleSoft component, including test and disaster-recovery systems that may be forgotten but still reachable. They should confirm the Oracle patch level, restrict Environment Management interfaces to trusted administrative networks, rotate credentials that could have been exposed and review logs for suspicious requests, newly installed remote-management tools and unfamiliar outbound connections.
Google’s earlier research said it notified more than 100 organisations whose internet addresses appeared to correlate with potentially vulnerable endpoints. That scale is a reminder that asset discovery is part of incident response. A team cannot patch a server it does not know is online.
What affected organisations should do
Security teams should preserve forensic evidence before rebuilding systems, particularly if they find web-shell activity, unexpected administrator accounts or unauthorised remote-management software. They should isolate affected hosts, apply Oracle’s remediation, review identity-provider and cloud logs, and determine whether data was accessed or exported. Legal, privacy and regulatory teams may need to assess notification obligations.
Defenders should also avoid overclaiming attribution. “ShinyHunters” is used publicly for a cluster of criminal activity, while Google’s UNC6240 label reflects the evidence available to its investigators. Attribution can change as infrastructure and operators overlap. The urgent task is containing the exploit path and protecting data.
Business leaders should expect disruption even when the affected application is not customer-facing. PeopleSoft can contain payroll, employee, student and supplier records, so an incident may interrupt routine administration and expose sensitive personal data. A response plan should identify who can authorise isolation, who communicates with staff and regulators, and how essential functions will continue while systems are examined. Clear ownership reduces the temptation to restore a compromised server before investigators understand what the attackers changed.
The Press of Asia recently covered another enterprise threat in its report on the Cisco ISE zero-day vulnerability. The common lesson is that perimeter devices and administrative platforms deserve emergency patching because compromise can provide privileged access far beyond a single server. India’s work on long-distance quantum-secure communication addresses future resilience, but today’s enterprise risk still depends on basic inventory, patching and monitoring.
The immediate takeaway
Any organisation running PeopleSoft should treat the latest report as an active exposure check, not a historical advisory. Patch status must be verified directly, externally accessible endpoints reduced and incident hunting performed even if a firewall rule is already in place. The absence of an alert does not prove the absence of compromise, especially when exploitation began before the vulnerability became public.
Sources: Google Cloud Threat Intelligence; Reuters report carried by Devdiscourse.





