CRITICALZero Day
Global

Despite ShinyHunters arrests after FBI jobs data breach, enterprises still have no answers about PeopleSoft risks

·Source: CSO Online

Updated:

Executive Summary

The theft of FBI employee data by hacking group ShinyHunters, and the subsequent shutdown of the FBI’s Peoplesoft-based jobs portal , is causing concern for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved, but there has still been no official word from either the F

Analysis

The theft of FBI employee data by hacking group ShinyHunters, and the subsequent shutdown of the FBI’s Peoplesoft-based jobs portal , is causing concern for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved, but there has still been no official word from either the FBI or Oracle about Peoplesoft’s alleged involvement. On Saturday, Reuters reported that a suspected member of ShinyHunters had been arrested in Jordan and has been cooperating with law enforcement to help identify other member of the group. The arrest comes a week after the arrest of another suspected ShinyHunters member by the Dutch National Police . In a video about that arrest, an FBI official warned gang members that arrests have a way of changing who is willing to talk, concluding, “You know how to find us, and we know how to find you.” Before the arrests, the gang told The Register it had discovered a new PeopleSoft zero-day hole and leveraged it to break into an FBI system, stealing information on all FBI employees. The FBI has since confirmed the breach without providing details. This wouldn’t be the first flaw ShinyHunters had found in PeopleSoft. It discovered a PeopleSoft zero-day hole in June that resulted in a flurry of extortion attempts , long after Oracle said it had patched the bugs . Oracle did not respond to a request for comment on the alleged new vulnerability. Significant risk exposure for enterprises Analysts and consultants played up the risk exposure from the potentially new vulnerability even as they sharply played down the implications of the arrest. Frank Dickson , principal analyst at Dickson Research, recommended that PeopleSoft users take immediate action. “If it is a new flaw, the patch is necessary but not sufficient. PeopleSoft customers should pull the Environment Management Hub and the Integration Broker off the public internet,” he said. “Doing so does not break normal user sessions.” He also encouraged users to quickly implement many of the recommendations from Google unit Mandiant’s report late last month on PeopleSoft security issues, especially “hunting for the web shells and outbound traffic Mandiant describes.” “For PeopleSoft shops, the to-do list is short,” Dickson said. “Apply Oracle’s patch. Disable or remove the Environment Management Hub if you do not use it. Search your logs for encoded variants of the PSEMHUB path, not just the literal string. If you find a web shell, treat the server as compromised and rotate every credential it could read.” This is a dangerous situation, he said: “An unpatched PeopleSoft flaw is a Sword of Damocles over every PeopleSoft shop But despite the extreme risk, even after the patch was released, rather than applying it, some organizations have opted for other mitigations. “Many organizations chose to block the vulnerable endpoint with web application firewall rules rather than patch,” Dickson said. “The attackers walked past those rules by changing a single character in the web address, writing ‘%50’ in place of the letter ‘P.’” Could signal a bigger problem However, IDC Research Director Philip Harris encouraged CISOs to view the FBI’s confirmation of its breach with caution, given the attack vector was not revealed. “ShinyHunters says it used a second, previously undocumented PeopleSoft preauth RCE zero-day, distinct from the CVE-2026-35273 flaw exploited in the earlier campaign,” he said. Yet, he pointed out, “no CVE has been assigned to it, it has not appeared on CISA’s Known Exploited Vulnerabilities catalog and Oracle has not commented on it. Every outlet covering this is explicit that the zero-day claim comes only from the threat actor, not from independent forensic confirmation or from Oracle. That distinction matters.” But if the hole is as the group has suggested, Harris said it signals a much bigger problem. “Assuming it is real, this would mean PeopleSoft has a second critical, unpatched preauth RCE in the same window as CVE-2026-35273, a pattern of recurring critical exposure rather than one isolated bug,” he said. “ShinyHunters’ own claim that they are already using it against other, unnamed Fortune 500 targets would mean every PeopleSoft customer is currently exposed to an unpatchable, undisclosed flaw with no vendor guidance to act on, a meaningfully worse position than the WAF-bypass story, since there is no mitigation to attempt while waiting on Oracle to confirm something it has not acknowledged.” Jeff Valdes , a director at consulting firm Acceligence, added that Oracle’s silence is unwarranted. “I think customers reasonably want more communication from the vendor,” he said. “They want to understand whether Oracle’s original guidance remains sufficient, whether there are additional mitigations customers should implement, whether Oracle is seeing anything through its own support organization that changes the risk picture, and whether there are configurations or architectural choices that materially increase exposure. Those are operational security questions that can be addressed without discussing attribution, arrests, investigative techniques or anything else that might interfere with an FBI investigation.”

Indicators of Compromise (1)

CVE (1)
CVE-2026-35273
Source Attribution

Originally published by CSO Online on Oct 6, 2026.

Related Threats