Oracle warned its business customers of a vulnerability rated critical in its PeopleSoft software, which large companies use for payroll and human resources management, a day after a cybercrime group took credit for exploiting the flaw as part of a massive hacking campaign.
The company issued a security advisory Thursday after the hacking group ShinyHunters claimed to have compromised more than 100 organizations using PeopleSoft servers.
Mandiant, Google's security division that investigates cyberattacks, warned in a blog post that the new Oracle flaw is the same bug that the ShinyHunters group is exploiting in a hacking campaign targeting PeopleSoft customers.
Oracle has not released a patch for the vulnerability at the time of writing, but the advisory states that the bug can be exploited over the Internet without requiring any password or other authentication.
The tech giant recommended that customers using PeopleSoft software apply its mitigations to prevent exploitation.
On Wednesday, members of ShinyHunters told TechCrunch that the gang exploited unpatched flaws in PeopleSoft servers to compromise companies. This bug is known as a zero-day. Because the affected company, in this case Oracle, didn't have time to fix it before it was discovered and exploited.
Mandiant also acknowledged that it had notified “more than 100 global organizations” (most of them in the United States) to restrict access to potentially vulnerable systems. The cybersecurity group says about two-thirds of these organizations have higher education, which is consistent with Shiny Hunters' previous claims.
“While some organizations were successful in blocking activity or remediating vulnerabilities, others experienced breaches that resulted in stolen data being published on ShinyHunters. [Data Leak Website]” Mandiant wrote.
Oracle did not respond to TechCrunch's request for comment.
Contact Us Do you have more information about this hacking campaign? Or is it another data breach? We would love to hear your thoughts. You can contact Lorenzo Franceschi-Bicchierai securely from any non-work device or network on Signal (+1 917 257 1382), Telegram and Keybase @lorenzofb, or email.
Members of ShinyHunters told TechCrunch this week that some of the hacked organizations include universities.
The hackers shared a message purportedly sent to one of the affected schools, in which they claimed to have stolen data including “hundreds of thousands of student records including names, home addresses, phone numbers, emails, dates of birth, gender, ethnicity, enrollment status, GPAs, majors, and student IDs for all campuses.”
PeopleSoft and its customers are the latest victims in a long series of hacking campaigns by the ShinyHunters gang targeting organizations that share the same vulnerable software.
Last year, the group targeted several companies that use software from companies including Salesforce, Gainsight, and education giant Instructor.
Once hackers identify vulnerable software and the companies using it, they attempt to steal company and customer data, threatening to release the data unless the victim pays a ransom.
Earlier this year, education technology company Instructure announced it had paid hackers after they breached its systems twice. As part of a hacking campaign, ShinyHunters defaced the login pages of several schools using Instructural's popular school information portal Canvas.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

