ShinyHunters Hit Universities Through PeopleSoft Zero-Day Before Oracle Patch

Mandiant ties a two-week extortion spree against Oracle PeopleSoft deployments to UNC6240, the cluster better known as ShinyHunters.

ThreatVectr Newsdesk· 2 min read
ShinyHunters Hit Universities Through PeopleSoft Zero-Day Before Oracle Patch
Share

ShinyHunters spent roughly two weeks inside enterprise Oracle PeopleSoft environments before the vendor said a word about the bug they were using.

The extortion crew — tracked by Mandiant as UNC6240 — exploited an unpatched flaw in PeopleSoft to steal data and demand payment for its suppression. Universities took the brunt of it. Intrusions ran from May 27 through June 9. Oracle's advisory did not land until June 10, making the vulnerability a true zero-day for the duration of the campaign.

ShinyHunters is not new. The group has run data-theft-and-extortion operations for years, with a track record that includes the Snowflake-customer breaches, AT&T, and a long catalogue of leaked databases listed on now-seized cybercrime forums. The crew typically skips encryption. They steal, they threaten, they post.

Mandiant's clustering treats UNC6240 as the operational arm behind this PeopleSoft push. Targets received extortion demands after data was exfiltrated from PeopleSoft instances. The amounts demanded varied by victim, and at least some of the affected universities have declined to pay, according to incident responders familiar with the matter. Others have not publicly confirmed their status.

PeopleSoft is widely deployed in higher education for student records, HR, and finance — which is exactly the data extortion crews want leverage over. A breach there is not a side-system problem. It is the student database, the payroll file, the donor records.

The sequencing matters. Attackers were already inside production environments before defenders had a CVE to track, a patch to deploy, or indicators to hunt on. By the time Oracle's quarterly cycle caught up, the data was gone.

Security teams running PeopleSoft should pull the Oracle advisory and confirm patch status across every environment, including dev and staging instances that frequently lag production. Authentication logs from late May through mid-June are the relevant window. Mandiant has published indicators tied to UNC6240's infrastructure; defenders should sweep for outbound connections to those hosts and unusual bulk reads against PeopleSoft tables.

No confirmed victim count has been released. Mandiant has described the campaign as targeted rather than opportunistic, which is consistent with ShinyHunters' historical preference for high-leverage data rather than spray-and-pray ransomware.

The group's leak site remains active. If non-paying universities are named, that will be where it happens first.

© 2026 Threat Vectr