ShinyHunters Resumes Large-Scale Attacks on Oracle PeopleSoft Systems Despite New Defenses
Key Takeaways
- •Mandiant says ShinyHunters shifted tactics to focus on organizations that deployed web application firewall rules but had not installed Oracle's patch for the PeopleSoft flaw.
- •The initial attacks ran from May 27 to June 9 and mainly targeted universities, while the renewed campaign spans education, technology, health care, agriculture, transportation, and government sectors across multiple countries.
- •ShinyHunters claims it breached the FBI through a PeopleSoft loophole, with a Reuters report saying leaked data included names and medical and psychiatric records of personnel in specific units, and the FBI says it is aggressively investigating.
- •A proxy filing shows Larry Ellison pledged 67 million more Oracle shares as loan collateral than a year earlier, a 19% increase worth roughly $9.2 billion at the $137.10 closing price.
- •Ellison canceled a trading plan on September 12, 2026, that would have allowed the sale of up to 50 million Oracle shares worth about $7.5 billion, after Oracle reported fiscal first-quarter revenue of $19.3 billion, up 30% year over year, with negative free cash flow of $5.40 billion.

ShinyHunters has relaunched a sweeping attack campaign against Oracle PeopleSoft, circumventing the defenses organizations deployed after breaches earlier this summer. Google's cybersecurity unit, Mandiant, said on Friday that the hacking group is conducting what it described as “mass exploitation” of a PeopleSoft security flaw.
The threat intelligence report was published just days after ShinyHunters claimed it had stolen FBI personnel data. Alphabet's Google (NASDAQ: GOOGL) said the attackers altered their methods after defenders responded to the initial wave.
The earlier attacks took place between May 27 and June 9 and primarily targeted universities. According to Mandiant, ShinyHunters subsequently shifted its strategy, concentrating on organizations that had added web application firewall rules — filters that screen traffic for known attack patterns — but had not applied Oracle's (NYSE: ORCL) patch. The renewed campaign has already reached scores of computers around the world.
Mandiant said the targeted industries include higher education, technology, health care, agriculture, transportation, and government, though it did not name any of the affected organizations. PeopleSoft is widely used to manage human resources and other critical internal operations, including at organizations with substantial security capabilities. Because the software sits at the center of HR operations, a single vulnerable installation can place personnel records across an entire organization at risk — the kind of sensitive data now at issue in the FBI case.
Mandiant: Tactics shifted after firewall defenses were added
According to Mandiant, the attackers adapted once security guidance was made public following the May and June incidents. Some organizations responded by deploying web application firewall filters to block the known attack method. However, those measures could not shield systems that had not installed Oracle's patch, and ShinyHunters focused on those unpatched environments. The group changed the way it reached the vulnerable PeopleSoft software while continuing to exploit the same underlying weakness, for which Oracle had already issued a patch. The sequence underscores a basic rule of mass exploitation response: filters can block a known attack method, but only the patch removes the flaw itself.
The campaign's fallout has extended to the Federal Bureau of Investigation. According to ShinyHunters, the FBI was breached through a PeopleSoft loophole, and a Reuters report said the leaked data included the names of individuals in specific FBI units along with their medical and psychiatric records. The FBI said on Wednesday that it was “aggressively investigating” the reported breach.
ShinyHunters has claimed responsibility for several major data breaches, and its FBI claim surfaced only days before Mandiant released the new findings on the wider PeopleSoft campaign. The latest activity followed the first wave and spans organizations across multiple countries and industries. Mandiant's report concentrated on systems that had firewall protections in place but lacked Oracle's patch.
Ellison pledges more Oracle shares, cancels $7.5 billion stock sale
In developments separate from the hacking campaign, Oracle disclosed new details about co-founder Larry Ellison's pledged shares. Ellison has put up 67 million more Oracle shares as collateral for personal loans than he had at the same point last year. A proxy filing released on Friday showed that the number of pledged shares is 19% higher than in 2025. At Oracle's closing price of $137.10, those shares are worth roughly $9.2 billion. Pledging shares as loan collateral ties an executive's personal finances to the company's stock, which is why proxy filings spell out the size of such arrangements.
Ellison is also helping finance a major media acquisition involving his son, David Ellison, whose company, Paramount Skydance Corp. (NASDAQ: PSKY), is seeking to acquire Warner Bros. Discovery Inc. (NASDAQ: WBD) in a transaction valued at $111 billion. The Ellison family has committed $47 billion in equity funding for the deal, with roughly $24 billion of that amount coming from three Middle Eastern sovereign wealth funds.
Ellison also reversed a large Oracle stock sale plan this month. On September 12, 2026, he canceled a plan that allowed him to sell as many as 50 million shares, a block worth approximately $7.5 billion at the stock's closing price. Oracle had disclosed the planned sale in a regulatory filing just one day earlier. Plans of this kind allow company insiders to schedule future share sales in advance under preset terms.
The trading plan had been adopted on June 22, 2026, and was scheduled to expire on October 24. Oracle said no shares were sold under the plan and added that Ellison “has no other plans to sell any of his Oracle stock.” The company did not provide a reason for the reversal.
The cancellation came after Oracle's fiscal first-quarter report, in which revenue rose 30% year over year to $19.3 billion and adjusted earnings per share reached $1.92. Free cash flow was negative $5.40 billion, compared with the $9.56 billion outflow analysts had expected. Oracle also raised its revenue backlog — a measure of contracted future revenue — to $664 billion, and the company continues to spend heavily on AI infrastructure even as free cash flow remains negative.