Invest1 publisher2 min readPublished
ShinyHunters routes around PeopleSoft firewall rules to hit systems still missing Oracle's patch
ShinyHunters is mass-exploiting PeopleSoft systems that added firewall rules after the summer breaches but skipped Oracle's patch, Mandiant said. For operators that wrote a filter and stopped, the remedy in the report is the patch Oracle already shipped.
The Investor · Invest desk

What happened
- Mandiant, Google's cybersecurity unit, said Friday that ShinyHunters is carrying out what it called mass exploitation of an Oracle PeopleSoft flaw.
- The group's first PeopleSoft wave ran from May 27 to June 9 and mostly hit universities.
- Mandiant said the new wave singles out organizations that added web application firewall rules after the first wave but had not installed Oracle's patch.
- Targets span higher education, technology, health care, agriculture, transportation and government, though Mandiant named none of the organizations.
- The FBI said Wednesday it was "aggressively investigating" after ShinyHunters claimed it had taken FBI personnel data.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision PeopleSoft operators that answered the first wave with firewall filters now have to put Oracle's patch on the schedule, since Mandiant found the filters covered only the published attack method.
- exposure Because PeopleSoft holds HR data, what an unpatched operator stands to lose is its staff's personal records, up to the medical and psychiatric files Reuters said were in the FBI leak.
- precedent The group changed tactics once the May-June guidance was public, so any future filter built from published guidance for a PeopleSoft flaw is temporary cover until the patch is installed.
The filters did what they were written to do. According to Mandiant, the group adjusted its tactics once security guidance went public after the May and June attacks [5]. Some companies had written web application firewall rules to block the known method, but those rules could not protect PeopleSoft installations that still lacked Oracle's patch [5]. ShinyHunters changed how it reached the vulnerable software and kept exploiting the same weakness [13].
As an allocation of effort, the organizations in this wave spent their response on the perimeter and skipped the patch Oracle had already issued for the bug [7][12]. PeopleSoft runs human resources and other internal operations, including at organizations with considerable security capabilities [11]. An unpatched instance therefore exposes employee data. Reuters reported that the data leaked in the FBI case included names of people in specific FBI units alongside their medical and psychiatric records [9]. The claim that PeopleSoft was the way in comes from ShinyHunters itself, and it surfaced days before Mandiant published [10].
Mandiant called the campaign "mass exploitation" [1]. The count Cryptopolitan gives is "scores of computers" around the world [2], which means tens of machines [1]. If confirmed intrusions stay at that scale, the campaign is a sweep of one known configuration: narrow in reach, serious for each victim. If the FBI's inquiry ties the personnel leak to PeopleSoft, the reach extends to federal HR files (the one victim with a public claim attached, and the only one the attackers have named).
I think the evidence supports the claim in its narrow form. A PeopleSoft system with a firewall rule and no patch is exactly the configuration Mandiant's report says this group is going after [12], and the fix for the underlying bug was already available [7]. The counter-thesis is that one threat intelligence report, relayed by one outlet, is a thin base for the word "mass". Cryptopolitan's account does not include a comment from Oracle. A patched installation among the victims would prove the patch-first reading wrong.
What to watch
- Whether the FBI's investigation attributes the personnel-data leak to a PeopleSoft intrusion, as ShinyHunters claims.
- A confirmed victim count or named organizations from Mandiant beyond "scores of computers".
- Any report of a patched PeopleSoft installation compromised through the new route, or an Oracle statement on the campaign.