ShinyHunters Renews Mass Attacks on Oracle PeopleSoft, Google Unit Says
Google's Mandiant says ShinyHunters has renewed mass exploitation of an Oracle PeopleSoft flaw, targeting organizations that patched firewalls but not the software.
Google's cybersecurity unit said on Friday that the hacking group ShinyHunters has renewed "mass exploitation" of a security flaw in Oracle's PeopleSoft software, after evading defenses put in place following attacks earlier in the summer.
Mandiant, a unit of Alphabet's Google, made the assessment in a threat intelligence report. The disclosure comes days after ShinyHunters claimed responsibility for stealing FBI personnel data.
The group exploited a bug in Oracle's PeopleSoft enterprise software in attacks between May 27 and June 9 that mainly affected universities, according to Mandiant. The hackers then adapted to defensive guidance published after that wave, targeting organizations that had implemented web application firewall rules but had not applied an update Oracle issued to patch the vulnerability.
Without identifying victims, Mandiant said the latest campaign affected dozens of systems globally across higher education, technology, healthcare, agriculture, transportation and government.
ShinyHunters has said it accessed FBI data through a PeopleSoft vulnerability. The claim could not be independently corroborated. Oracle did not respond to requests for comment.
In a statement issued Wednesday, the FBI said it was "aggressively investigating" the reported breach. ShinyHunters exposed the names of personnel working in sensitive FBI units and obtained medical and psychiatric records, according to earlier reporting.
The evolving nature of the attacks is likely to raise concerns among organizations that depend on PeopleSoft for human resources and other critical functions, and to heighten worries about the exposure of even well-resourced institutions.