INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters PeopleSoft Breach Exploit Targets Public Data

| 2026-06-29 20:30 CRITICAL LOW
Executive Summary AI-generated
The ShinyHunters extortion group has breached the systems of numerous organizations, including the National Association of Insurance Commissioners (NAIC), a U.S. insurance regulatory organization present in all 50 states. The breach occurred after an unauthorized party exploited a zero-day vulnerability in an Oracle PeopleSoft server, resulting in the theft of publicly available data and outdated logs. This is not the first time ShinyHunters has targeted organizations with stolen data, including education sector targets that had previously been extorted by the group.
Technical Mitigations AI-generated
* Implement a robust security patching strategy to address zero-day vulnerabilities like CVE-2026-35273, and regularly update software and systems with the latest security patches. * Conduct regular vulnerability scanning and penetration testing to identify potential entry points for attackers and ensure that defenses are up-to-date. * Use secure coding practices and follow best security guidelines when developing or deploying applications, such as using secure authentication mechanisms and validating user input. * Regularly review and update incident response plans to ensure that they remain effective in responding to emerging threats like ShinyHunters' PeopleSoft breach. * Consider implementing a cloud security gateway or network access control (NAC) system to provide additional protection against lateral movement within networks.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-35273CVE-2026-35273
Target & Sectors
EUROPE EUROPE NORTH_AMERICA NORTH_AMERICA educationeducation
Incident Timeline
‎2026/06/08
Threat actors exploited CVE-2026-35273 in a PeopleSoft breach targeting around 454,600 current and former students of the UK university.
target_region United Kingdom
general_metric 454,600 current students
vulnerability CVE-2026-35273
organisation Google
organisation IP
general_metric 100 global orgs
‎June 11
The PeopleSoft system of the identified organization was accessed by an unauthorized party on June 11.
‎June 25
ShinyHunters used AWS infrastructure configs to target the National Association of Insurance Commissioners' (NAIC) systems.
infrastructure 3.1
organisation Vision
organisation SERFF
organisation UCAA
data_breach 3.1 TB
data_breach 105,000 files
general_metric 264,000 insurer
financial 2,000 payment records
general_metric 45,000 rating agency
‎between 2017 and 2024
ShinyHunters used AWS infrastructure configs to store stolen data.
infrastructure 3.1
organisation Vision
organisation SERFF
organisation UCAA
data_breach 3.1 TB
data_breach 105,000 files
general_metric 264,000 insurer
financial 2,000 payment records
general_metric 45,000 rating agency
‎between May 27 and June 9
Threat actors exploited CVE-2026-35273 in the PeopleSoft breach targeting more than 100 global organizations between May 27 and June 9.
vulnerability CVE-2026-35273
organisation Google
organisation IP
general_metric 100 global orgs
‎2026/06/29
ShinyHunters stole public data from Instructure's PeopleSoft digital learning platform.
organisation Council
victims 100 organizations
organisation CVE
organisation the University of Nottingham
organisation Oracle PeopleSoft
data_breach 429,000 pilfered files
organisation Canvas
organisation the Council of Europe
data_breach 297 GB
organisation ShinyHunter
organisation The Register ’s
organisation NAIC
organisation ShinyHunters
organisation PeopleSoft
organisation Council of Europe
organisation PII
organisation SERFF (System for Electronic Rate
organisation OPTins
organisation State-Based Systems
organisation BleepingComputer However
organisation BleepingComputer
organisation Oracle
organisation EDR
organisation The Register
organisation Salesforce
organisation Infinite Campus
Tactical Metrics
Metrics
infrastructure
‎3.1
Software Version
Metrics
data_breach
3
Tb
Metrics
data_breach
105,000
Files
Metrics
financial
2,000
Payment Records
Metrics
victims
100
Organizations
Metrics
data_breach
429,000
Pilfered Files
Metrics
data_breach
297
Gb
Intelligence Sources
The Register - Cybercrime 2026-06-15
BleepingComputer 2026-06-29