Key points
- Mandiant reports renewed attacks on PeopleSoft
- They targeted servers that skipped Oracle's patch
- The group claims it stole medical records from FBIjobs.gov
ShinyHunters is exploiting an already-patched flaw in Oracle's (ORCL) PeopleSoft software, bypassing firewall rules at organizations that had not installed the fix, Google's Mandiant unit reported Friday.
Mandiant said the hackers planted web shells, which give attackers remote access, on dozens of systems worldwide across universities, businesses, healthcare, and government. Mandiant did not name the victims.
Separately, ShinyHunters claims it stole psychiatric and medical records of FBI applicants and staff through PeopleSoft. That claimed connection has not been independently corroborated, and Mandiant's report does not mention the FBI.
A patched flaw, attacked again
The flaw, CVE-2026-35273, affects PeopleTools versions 8.61 and 8.62. Oracle patched it on June 10 and rated it 9.8 out of 10 for severity. "This vulnerability is remotely exploitable without authentication," Oracle's security alert says. The US Cybersecurity and Infrastructure Security Agency added it to its list of actively exploited flaws on June 12.
ShinyHunters first used the flaw as a zero-day, before any patch existed, from May 27 to June 9, mostly against universities, according to Mandiant. After that wave, some organizations added firewall rules to block requests to the vulnerable part of PeopleSoft instead of installing the patch.
The hackers got around those rules by changing a single character in the web address to its encoded form, which the firewalls didn't recognize but PeopleSoft still read normally, Mandiant said. "WAF rules and path-based blocking are not a substitute for patching," the report says.
Oracle didn't respond to requests for comment from Reuters and hasn't issued a new advisory for the September attacks.
The FBI records
ShinyHunters says it broke into FBIjobs.gov, the FBI's applicant site, and stole what it claimed was 2 to 3 terabytes of data. The group circulated several purported medical records to reporters this week. According to Reuters, some documents were partly authenticated, but the scope of the alleged theft, and whether the samples represented a larger collection, could not be established.
The FBI declined to comment on the records to Reuters. Earlier in the week, the bureau said it was "actively and aggressively investigating this matter" and working with the third-party providers that support FBIjobs.gov.
Oracle shares closed at $137.10 on Friday, down 1.8%, before the Reuters reports were published. Oracle has been under pressure over its data center financing, including loans banks quoted at a discount this month.



