ClosedMedium impactAI Refreshed

ShinyHunters extortion gang claims data theft from 100+ Oracle PeopleSoft instances

Occurred 20 May 2026Β·Detected 15 Jun 2026Β·
πŸ‡ΊπŸ‡Έ Global targeting of Oracle PeopleSoft server instances, with confirmed victim in Nottingham, UK28 reportsEnded 1 Jul 2026
CyberEnvironmental & IndustrialPropertyCyberCasualty & Liability

ShinyHunters is conducting a data-theft and extortion campaign against Oracle PeopleSoft, with active exploitation of CVE-2026-35273 (PeopleTools missing-authentication) corroborated by CISA (KEV listing, 12 June 2026), Google/Mandiant and Oracle's own critical security alert. Higher education is the dominant affected sector; the University of Nottingham is the only named confirmed victim, with personal data of approximately 454,600 current and former students (including payment, credit card and passport data across UK, Malaysia and China campuses) published on the ShinyHunters leak site. Google/Mandiant and ShinyHunters reporting point to ~100 organisations and ~300 PeopleSoft instances affected. No insured loss estimate, named London Market cyber claim or sector-spread beyond education has been disclosed in the supplied context.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. Materiality holds at moderate. Authoritative corroboration (CISA KEV, Google/Mandiant confirmation, Oracle security alert) has materially de-risked the threat-actor narrative and confirms active exploitation of a critical flaw on a widely deployed enterprise ERP/HR platform, but severity remains capped: only one named confirmed victim, no loss estimate, no named insured London Market cyber claim, and Oracle has not publicly labelled CVE-2026-35273 a zero-day. The single quantified victim (Nottingham, ~454,600 PII records including payment and passport data) floors single-victim severity in the low-to-mid single-digit millions range for higher-education extortion PII events, but systemic severity cannot be scaled without further confirmed-victim disclosure.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

3 active matches

  • TRIA Certified Areas
    Rule-basedConfidence 100%
  • Pacific Ring of Fire
    Rule-basedConfidence 100%
  • Caribbean Hurricane Zone
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

πŸ‡¨πŸ‡³ ChinaπŸ‡¬πŸ‡§ United KingdomπŸ‡²πŸ‡Ύ MalaysiaπŸ‡ΉπŸ‡Ό TaiwanπŸ‡ΊπŸ‡Έ United States

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts