The notorious cybercriminal group ShinyHunters has claimed to have hacked the Oracle PeopleSoft servers of more than 100 organizations, many of them universities, ShinyHunters members told TechCrunch on Wednesday. This breach was first reported by BleepingComputer.
PeopleSoft is enterprise software designed to manage payroll, human resources, administration, and other operations.
This news shows that despite being one of the most prominent and prolific cybercrime groups of the moment, Shiny Hunters is not slowing down and has turned large-scale hacking into its specialty. The group's modus operandi is to find vulnerabilities in popular software and put many victims at risk at once.
“Student, applicant, financial aid, immigration, health, and administrative data has been compromised,” said a message the hacker allegedly sent to one of the victims. The hackers claimed to have stolen student records, including home addresses, phone numbers, email addresses, dates of birth, and more.
The hacker added that most of the targeted schools had already been compromised in a previous unrelated campaign.
The group's original goal was to compromise FBI PeopleSoft servers, according to the group, in order to post a statement denying that ShinyHunters was behind the swatting activity that the FBI warned about last month. Members said the attempt failed.
Oracle did not respond to requests for comment.

