Key facts
- A zero-day vulnerability in PeopleSoft has been exploited, affecting hundreds of organizations.
- Stolen data has been published on the ShinyHunters data leak site.
A zero-day vulnerability in PeopleSoft has been exploited by threat actors, leading to data theft from hundreds of organizations. Stolen data has been published on the ShinyHunters data leak site, with one victim reportedly losing 48GB.

This zero-day exploit highlights a significant vulnerability in widely used enterprise software, exposing hundreds of organizations to data theft and reputational damage. The success of the ShinyHunters group underscores the ongoing threat posed by sophisticated cybercriminal operations.
A zero-day vulnerability affecting PeopleSoft has been exploited by threat actors, leading to data breaches at hundreds of organizations. Mandiant reported that some compromised entities experienced data theft, with the stolen information subsequently published on the ShinyHunters data leak site (DLS).
Analysis of a bash script found in a staging environment revealed that the attackers conducted reconnaissance on affected organizations. This included mapping PeopleSoft configurations and examining process scheduler and WebLogic server XML configurations. The threat actors then established an outbound SSH connection to an IP address hosting ShinyHunters’ DLS, where the stolen data, compressed using the zstd tool, was uploaded. The DLS claimed to have recovered 48GB of data from a single victim.
ShinyHunters has been active since at least 2019, carrying out numerous hacks against large companies. Their methods include exploiting cloud misconfigurations, software vulnerabilities, stealing OAuth tokens, supply chain attacks, and social engineering tactics. Mandiant and Rapid7 are providing detailed indicators of compromise and advising PeopleSoft customers on immediate protective measures.
Pick the topics you care about. Get only what matters, on your cadence.