ShinyHunters extortion gang claims data theft from 100+ Oracle PeopleSoft instances
ShinyHunters is conducting a data-theft and extortion campaign against Oracle PeopleSoft, with active exploitation of CVE-2026-35273 (PeopleTools missing-authentication) corroborated by CISA (KEV listing, 12 June 2026), Google/Mandiant and Oracle's own critical security alert. Higher education is the dominant affected sector; the University of Nottingham is the only named confirmed victim, with personal data of approximately 454,600 current and former students (including payment, credit card and passport data across UK, Malaysia and China campuses) published on the ShinyHunters leak site. Google/Mandiant and ShinyHunters reporting point to ~100 organisations and ~300 PeopleSoft instances affected. No insured loss estimate, named London Market cyber claim or sector-spread beyond education has been disclosed in the supplied context.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. Materiality holds at moderate. Authoritative corroboration (CISA KEV, Google/Mandiant confirmation, Oracle security alert) has materially de-risked the threat-actor narrative and confirms active exploitation of a critical flaw on a widely deployed enterprise ERP/HR platform, but severity remains capped: only one named confirmed victim, no loss estimate, no named insured London Market cyber claim, and Oracle has not publicly labelled CVE-2026-35273 a zero-day. The single quantified victim (Nottingham, ~454,600 PII records including payment and passport data) floors single-victim severity in the low-to-mid single-digit millions range for higher-education extortion PII events, but systemic severity cannot be scaled without further confirmed-victim disclosure.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialGeographic Zone Matches
3 active matches
- TRIA Certified AreasRule-basedConfidence 100%
- Pacific Ring of FireRule-basedConfidence 100%
- Caribbean Hurricane ZoneRule-basedConfidence 100%
Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.
Affected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts