Threat Analysis
Payroll Data Exposed by ShinyHunters Oracle PeopleSoft Breach
written by:
Dominic Reilly

Nissan Americas filed breach notifications with the California Attorney General on June 30 confirming that current and former employees across the US, Canada, Mexico, and Brazil had payroll records, banking information, and Social Security numbers exposed following exploitation of a zero-day vulnerability in Oracle PeopleSoft PeopleTools. ShinyHunters exploited CVE-2026-35273 — an unauthenticated remote code execution flaw with a CVSS score of 9.8 — from May 27 through June 9, compromising more than 300 PeopleSoft instances across over 100 organizations before Oracle acknowledged the flaw or issued mitigations. Google's Mandiant team confirmed active exploitation and notified more than 100 organizations. Oracle's own breach notification language — "the personnel records of hundreds of companies may have been obtained" — puts the disclosed victim count firmly at a floor. The National Association of Insurance Commissioners confirmed it was breached and has suspended data feeds and investment designation work. The University of Nottingham refused to negotiate; ShinyHunters published 40+ GB of records covering 454,600 current and former students. The immediate CISO decision point is not whether to patch — that window passed on June 10 — but whether your Oracle PeopleSoft environment, or any vendor running PeopleSoft on your behalf, was among the compromised instances.
Fourteen Days of Uncontested Access Before Oracle Knew
ShinyHunters began exploiting CVE-2026-35273 on May 27. The flaw sits in the Environment Management component of Oracle PeopleSoft PeopleTools and requires no credentials — attackers targeted the PSEMHUB endpoint and abused the Integration Broker for server-side request forgery. Oracle did not disclose the vulnerability or issue emergency mitigations until June 10, leaving a 14-day zero-day window with no patch to apply and no advisory to act on.
ShinyHunters told BleepingComputer they breached more than 300 PeopleSoft instances across 100+ organizations during that window. Mandiant independently confirmed exploitation and notified over 100 organizations with matching infrastructure. CISA added CVE-2026-35273 to its Known Exploited Vulnerabilities catalog on June 11. By that date, data exfiltration was complete.
Victim notifications have arrived in waves. NAIC detected its breach on June 11 and disclosed June 17. The University of Nottingham confirmed compromise of a "significant amount" of student data and is cooperating with a criminal investigation. Nissan Americas disclosed June 30. ShinyHunters has published stolen data from organizations that declined to negotiate and has set public deadlines for others still under extortion. The investigation timeline at most victim organizations is ongoing.
Payroll Records Across Four Countries, Insurance Regulators, and 100+ Education Institutions
Sector | Confirmed Exposure | Key Risk |
Automotive | Nissan Americas employees — US, Canada, Mexico, Brazil; SSNs, banking data, payroll records | Direct deposit fraud, tax identity theft |
Insurance Regulation | NAIC: 3.1TB claimed; insurer filings, investment data; data feed operations suspended | Financial system operational disruption |
Higher Education | 68% of 100+ victim organizations (Mandiant, 2026); University of Nottingham: 454,600 records published | Student PII, financial aid, research records |
Broader enterprise (undisclosed) | Oracle: "hundreds of companies" had personnel records potentially obtained | Victim count still expanding |
The 68% higher education concentration reflects PeopleSoft's deployment footprint in that sector, not deliberate targeting by ShinyHunters. That distinction matters: 32% of confirmed victims sit outside education, and Oracle's own breach notification language signals the disclosed list has not stopped growing.
Fraud Risk Lands in Employee Bank Accounts Before Investigations Close
Hard financial totals for this campaign are not yet confirmed. ShinyHunters' documented extortion demands for comparable operations run 4 to 20 Bitcoin per organization — approximately $400,000 to $2.3 million per victim at current valuations (Vali Cyber, 2026). NAIC's operational consequences are confirmed: suspension of insurance data feeds and pausing of investment designation work, disrupting downstream functions that regulators and insurers depend on.
ShinyHunters' prior campaigns provide the cost baseline. AT&T paid a $370,000 ransom in the 2024 Snowflake campaign to secure deletion of 109 million call records (Huntress, 2026). The FBI issued a formal advisory in May 2026 recommending against payment; at least one 2026 victim paid in a separate campaign and ShinyHunters honored the deletion agreement. Neither outcome eliminates the regulatory exposure that follows a confirmed breach notification filing.
For Nissan Americas: banking and direct deposit data in attacker hands creates a payroll fraud timeline measured in days, not weeks. Nissan has already restricted payslip access and direct deposit changes network-wide while implementing additional identity verification. That is the right response — and the model for any organization that has not yet confirmed its exposure status.
Why Oracle ERP Doesn't Get Firewall-Level Patch Urgency — And Why That Has to Change
Most enterprise security programs apply their tightest patch SLAs — 24 to 72 hours — to perimeter devices: firewalls, VPNs, edge infrastructure. Oracle PeopleSoft sits in a different mental bucket. HR or Finance IT administers it. It's patched on Oracle's quarterly CPU schedule. Security teams classify it as "internal" because it manages employee data rather than customer-facing traffic.
That classification was wrong for every organization whose PSEMHUB endpoint was internet-reachable. ShinyHunters didn't need internal network access. They connected over HTTP, without credentials, to a component most security teams didn't know was externally exposed. The 14-day zero-day window is not the program failure — no patch existed to apply. The failure is that a system holding every employee's Social Security number and bank routing information was reachable from the open internet, monitored by HR IT, and outside the scope of any security tool watching for anomalous access patterns.
This campaign will repeat. Oracle E-Business Suite Payments (CVE-2026-46817, CVSS 9.8) was confirmed under active exploitation by Defused honeypots on June 27 — six weeks after patching, before any public proof-of-concept existed (Defused, 2026). ShinyHunters and Cl0p have each run successful zero-day campaigns against Oracle ERP products within the past nine months. Oracle's ERP stack is now a tracked, recurring attack surface, and quarterly patch cycles create a systematic window that attackers are actively timing against.
What To Do About It
1. Audit every Oracle PeopleSoft PeopleTools deployment for internet-exposed PSEMHUB endpoints and confirm CVE-2026-35273 mitigations are applied — Oracle's emergency guidance was available June 10; any unverified instance may still be reachable — this directly addresses the board question of whether your employees' payroll data is in ShinyHunters' possession.
2. Run a payroll integrity check against a pre-May 27 snapshot of all direct deposit configurations this week — bank routing and account numbers are the specific data category extracted, enabling deposit redirection that activates before your breach investigation closes — this addresses workforce financial harm, which carries both regulatory and HR leadership liability.
3. Issue breach notification inquiries to any HR managed-service provider or Oracle PeopleSoft hosting vendor by end of this week — Oracle's disclosure language covers "hundreds of companies"; your third-party HR processor may have been compromised without notifying you, and your breach notification clock starts at discovery, not at vendor confirmation — this addresses state AG and SEC notification timelines.
4. Reclassify Oracle ERP products (PeopleSoft, E-Business Suite, WebLogic) as Tier 1 patch priority this quarter — CVE-2026-46817 in Oracle EBS Payments is already under active exploitation; the quarterly CPU patch cycle creates a documented, repeating exposure window on systems that route wire transfers and ACH batches — this addresses CFO and legal exposure from a provable failure to patch critical financial infrastructure on a reasonable timeline.
5. Activate employee fraud protection measures for the full affected population now, not after the investigation closes — Nissan's victim determination is still incomplete; confirmed counts expand as investigations progress, and employees who experience payroll fraud while your organization determines scope face real financial harm — this addresses workforce duty-of-care, which boards will hear about from HR leadership before legal has finished its assessment.
In Brief
CVE-2026-45659, Microsoft SharePoint (CVSS 8.8) — Federal Patch Deadline Was July 4: Storm-2603, the threat actor linked to Warlock ransomware, is actively exploiting this deserialization flaw in on-premises SharePoint Server. Any authenticated user with Site Member access — the lowest functional permission level — can trigger remote code execution. Shadowserver tracks 10,000+ internet-facing SharePoint servers currently (Shadowserver, 2026). Microsoft patched May 21; CISA KEV listed. Microsoft's own incident response team documented a parallel, concurrent second threat actor operating inside the same Storm-2603 intrusion — meaning what presents as a ransomware incident may be masking a deeper, quieter compromise.
FortiBleed Confirmed as INC Ransom and Lynx Ransomware Supply Chain: SOCRadar researchers, after gaining access to FortiBleed operational infrastructure via an OPSEC lapse, found a single operator simultaneously managing negotiation panels for both INC Ransom and Lynx ransomware groups (SOCRadar, 2026). The campaign installed credential-sniffing tools on approximately 19,000 FortiGate devices, completed 354 confirmed full attack chains, and produced 12 ransomware deployments. If your FortiGate estate hasn't been audited for FortiOS-resident traffic sniffers since this campaign was disclosed, that audit is the week's most urgent pending action.
CVE-2026-46817, Oracle EBS Payments (CVSS 9.8) — Active Exploitation Without a Public PoC: Defused honeypots recorded the first exploitation of this unauthenticated flaw on June 27, six weeks after Oracle's May patch — before any public proof-of-concept existed (Defused, 2026). The targeted endpoint processes ACH batches, wire transfer instructions, and EFT file transmissions. Shadowserver identifies approximately 950 internet-facing EBS instances currently. This is the second Oracle ERP zero-day exploited in the wild in nine months, following Cl0p's October 2025 EBS campaign.
CL-STA-1062 Chinese APT Confirmed Against Southeast Asian Electricity and Water Utilities: Palo Alto Networks Unit 42's June 25 report documents 10+ confirmed intrusions by this group against electricity providers, water utilities, and military organizations across multiple Southeast Asian countries (Palo Alto Networks Unit 42, 2026). The group deploys a custom backdoor, TinyRCT, alongside Mimikatz and SoftEther VPN. Unit 42 assesses high confidence this is the same cluster Cisco Talos tracks as UAT-7237. The pattern — lateral movement across government-linked organizations in the same country, sustained access over months — is consistent with Volt Typhoon's pre-positioning model, not opportunistic intrusion.
The pattern across this week's findings is consistent: the systems holding the most sensitive data — HR platforms, financial ERP, payroll infrastructure — sit outside the monitoring and patch programs security teams built for perimeter and endpoint environments. ShinyHunters' Oracle campaign succeeded not because perimeter controls failed, but because no one was watching the component that did. Over the next 60 to 90 days, expect the confirmed victim count from the PeopleSoft campaign to continue climbing as vendor-side investigations complete and breach notifications reach additional state AGs. Oracle's second actively exploited ERP flaw in the same quarter, combined with the FortiBleed-to-ransomware pipeline, indicates that financial and HR infrastructure has moved from incidental to primary target real estate for both extortion groups and the access brokers that supply them. Programs that treat ERP patch cycles as a vendor scheduling matter — rather than a security program priority — are the ones filing the next round of breach notifications.
You might want to read

Threat Analysis
Klue OAuth Breach Exposes Salesforce Data at 11 Security Firms
Icarus Extortion Group Exploits Abandoned Klue Credential, Stealing Salesforce CRM Data from Huntress, LastPass, Recorded Future, and Eight Others

Threat Analysis
146% in 60 Days: Inside the QR Phishing Surge Your Stack Can't See
Microsoft reported a 146% jump in QR phishing between January and March 2026. The attack lives inside an image, runs on a personal device, and never touches your network. Why your stack misses it — and what the 96-minute-vs-96-hour asymmetry actually looks like.

Industry Insights
98 mins vs. 5 days: The Speed Gap That's Defining Modern Cybersecurity
Average attacker breakout time has dropped under 98 minutes. Average threat investigation time is still measured in days. Why is the speed gap is widening? And what would it take to close it?