Hackers renew attacks on Oracle (ORCL) PeopleSoft and claim theft of FBI medical records

A hooded figure with a hidden face typing on a laptop

Key points

  • Mandiant reports renewed attacks on PeopleSoft
  • They targeted servers that skipped Oracle's patch
  • The group claims it stole medical records from FBIjobs.gov

ShinyHunters is exploiting an already-patched flaw in Oracle's (ORCL) PeopleSoft software, bypassing firewall rules at organizations that had not installed the fix, Google's Mandiant unit reported Friday.

Mandiant said the hackers planted web shells, which give attackers remote access, on dozens of systems worldwide across universities, businesses, healthcare, and government. Mandiant did not name the victims.

Separately, ShinyHunters claims it stole psychiatric and medical records of FBI applicants and staff through PeopleSoft. That claimed connection has not been independently corroborated, and Mandiant's report does not mention the FBI.

A patched flaw, attacked again

The flaw, CVE-2026-35273, affects PeopleTools versions 8.61 and 8.62. Oracle patched it on June 10 and rated it 9.8 out of 10 for severity. "This vulnerability is remotely exploitable without authentication," Oracle's security alert says. The US Cybersecurity and Infrastructure Security Agency added it to its list of actively exploited flaws on June 12.

ShinyHunters first used the flaw as a zero-day, before any patch existed, from May 27 to June 9, mostly against universities, according to Mandiant. After that wave, some organizations added firewall rules to block requests to the vulnerable part of PeopleSoft instead of installing the patch.

The hackers got around those rules by changing a single character in the web address to its encoded form, which the firewalls didn't recognize but PeopleSoft still read normally, Mandiant said. "WAF rules and path-based blocking are not a substitute for patching," the report says.

Oracle didn't respond to requests for comment from Reuters and hasn't issued a new advisory for the September attacks.

The FBI records

ShinyHunters says it broke into FBIjobs.gov, the FBI's applicant site, and stole what it claimed was 2 to 3 terabytes of data. The group circulated several purported medical records to reporters this week. According to Reuters, some documents were partly authenticated, but the scope of the alleged theft, and whether the samples represented a larger collection, could not be established.

The FBI declined to comment on the records to Reuters. Earlier in the week, the bureau said it was "actively and aggressively investigating this matter" and working with the third-party providers that support FBIjobs.gov.

Oracle shares closed at $137.10 on Friday, down 1.8%, before the Reuters reports were published. Oracle has been under pressure over its data center financing, including loans banks quoted at a discount this month.

Frequently asked questions

What did Google say about ShinyHunters and Oracle PeopleSoft?

Google's Mandiant unit said on September 25, 2026 that ShinyHunters renewed mass exploitation of CVE-2026-35273, a flaw in Oracle's PeopleSoft software, deploying web shells on dozens of systems in sectors including higher education, healthcare, and government. The attacks targeted organizations that used firewall rules but didn't install Oracle's patch.

Is there a patch for the Oracle PeopleSoft flaw?

Yes. Oracle patched CVE-2026-35273, which affects PeopleTools 8.61 and 8.62, on June 10, 2026 and rated it 9.8 out of 10 for severity. Mandiant said firewall rules and path-based blocking are not a substitute for patching.

Did ShinyHunters steal FBI medical records?

The group says it did. ShinyHunters says it broke into FBIjobs.gov, the FBI's applicant site, and stole 2 to 3 terabytes of data. According to Reuters, some of the purported medical records the group shared with reporters were partly authenticated, but the scope of the alleged theft could not be established.

Did the FBI breach come through Oracle PeopleSoft?

ShinyHunters says so, but Reuters said it hasn't been able to corroborate that claim, and Mandiant's report doesn't mention the FBI. The FBI has said it is investigating the reported breach.

More on ORCL

Dennis Singleton
Dennis Singleton

Dennis Singleton was born in Australia and later moved to the United States. He has spent years following the markets, but what keeps his attention is how AI is built. He writes about the companies behind the technology, from semiconductor designers and advanced packaging to photonics, memory, networking, and the hardware powering modern AI. His approach starts with filings, earnings, and industry research, then translates the important details into clear, straightforward analysis without unnecessary hype.