HomeSecurityShinyHunters: New wave of attacks – see if your data was leaked and...

ShinyHunters: New wave of attacks – see if your data was leaked and what to do

The ShinyHunters group is back with a new wave of attacks, and Google is sounding the alarm. On September 25, 2026, Mandiant and Google’s Threat Intelligence Group (GTIG) warned that hackers had once again launched massive attacks on Oracle PeopleSoft systems around the world, just days after claiming to have breached the FBI. If you’re wondering if your data was leaked, this article will tell you exactly what happened, who was affected, and what you should do immediately.

PeopleSoft is software used by universities, hospitals, government agencies, and large corporations to manage payroll, staff, and students. In other words, it's where some of the most sensitive data an organization can have about its people lives: names, addresses, phone numbers, payment information, and medical information.

See also: ShinyHunters: Claims FBI breach via Oracle PeopleSoft zero-day

User checks if your data was leaked after the new ShinyHunters attack

What Google announced

According to Google's report, ShinyHunters, which the company tracks under the codename UNC6240, is again exploiting the CVE-2026-35273 in Oracle PeopleSoft. This is a critical security flaw that allows someone to execute commands on the server without even having to log in. The same group had used the vulnerability from May 27 to June 9, primarily against universities, before Oracle released an emergency security update on June 10.

But many organizations never installed the fix. Instead, they simply added rules to their web application firewall (WAF) to block this particular attack path. Hackers quickly found a way around it: they changed the encoding of a single letter in the address they were targeting, and the rules stopped working. Google says they installed remote access malware (web shells) on dozens of systems worldwide, in organizations ranging from higher education, technology, healthcare, agriculture, transportation, and government.

The new wave comes three days after ShinyHunters claimed to have hacked the FBI’s recruitment page and obtained employee and candidate information. The FBI said it was actively investigating the case, but did not confirm the extent of the leak, and Reuters noted that it could not independently verify the group’s claims.

Oracle PeopleSoft servers targeted by ShinyHunters

Who are ShinyHunters?

ShinyHunters is one of the most active data theft and extortion groups in the world. They have been linked to breaches at companies including AT&T, Ticketmaster, and Santander, as well as a major campaign against Salesforce customers in which they used phone scams to trick employees. In September alone, the group claimed to have stolen hundreds of millions of records from McKesson, hacked the Cl0p ransomware gang’s leak site, and targeted the FBI.

The way they work is well known: they steal large amounts of data, demand money from the organization not to publish it, and, if they are not paid, they leak or sell it. This is where the danger for the average user begins, because this information ends up in the hands of scammers who use it for targeted messages and phone calls.

Does this leak concern me?

Google has not released the names of the organizations affected by the new wave, nor has any victim been reported in Greece so far. However, ShinyHunters has a track record of leaking from international services used by millions of people in our country. The SecNews technical team believes that you should be more careful if:

  • you are studying or working at a university abroad, or have applied to one,
  • you work in a multinational, hospital or public institution that uses PeopleSoft,
  • you have an account with any of the companies that have already been affected by the group.

How to see if your data has been leaked

The easiest way is to use the free service Have I Been Pwned, run by security researcher Troy Hunt. You enter your email address on the homepage, and the service shows you which known breaches it's been in, along with the types of data that was exposed, such as passwords, phone numbers, or addresses. You can also sign up to be notified if your email address appears in a future breach.

Keep in mind that a new leak doesn't appear immediately on such services, because the data has to be detected and verified first. So if the check doesn't turn up anything today, that doesn't necessarily mean you're safe. Additionally, Google (via Password Manager and Chrome) and Apple (via the password manager app on your iPhone) notify you if any of your saved passwords have been leaked. It's worth taking a look there too.

See also: AI scams: Fake bank calls and deepfakes – how to avoid falling victim

Checking accounts and changing passwords after a data breach

What to do immediately

Whether the test shows anything or not, a few simple steps can significantly reduce your risk. Most of them only take a few minutes:

  1. Change your passwords, starting with email and e-banking. If you use the same password on multiple services, change it everywhere.
  2. Use a password managerso that each account has a different and strong password without having to remember them.
  3. Enable two-factor authentication (2FA), preferably with a verification app, security key, or passkeys instead of SMS.
  4. Enable alerts in the bank for every transaction, so you can immediately detect anything suspicious.
  5. Don't respond to messages that "know" a lot about you. An email or SMS with your name, address, or employer is not proof that it is genuine.

The last step is perhaps the most important. After every major leak, there is almost always a wave of targeted scams: fake notifications from your “employer,” “university,” or “bank” that use your real details to make it look convincing. ShinyHunters, after all, is known for its phone scams. If someone calls or texts you asking for codes or payment, hang up and contact the organization using their official details.

Security key for two-factor authentication

What should organizations do?

For those managing PeopleSoft, Google's message is clear: firewall rules are not a substitute for updating. Mandiant recommends immediately installing the patch Oracle released on June 10, disabling the Environment Management Hub (EMHub) service where it is not being used, and cutting off administrative functions from the public internet. Organizations that have not installed the patch should also check their systems for signs of compromise, as attacks may already have occurred.

Frequently asked questions

Are there any victims in Greece? So far, no Greek victims of the new wave have been announced. Google has not released the names of organizations.

If Have I Been Pwned shows nothing, am I safe? Not necessarily. New breaches take time to register. Changing passwords and enabling 2FA protect regardless of the outcome.

Should organizations pay extortionists? The FBI recommends against paying ransoms, as paying does not guarantee that data will be deleted and encourages new attacks.

ShinyHunters shows once again that an unpatched vulnerability can expose thousands of people, even months after the fix was released. For the average user, the defense is simple: check if your details were leaked, change passwords, enable 2FA, and be suspicious of any message that seems “too personal.”.

See also: ShinyHunters hacked the dark web site of the Cl0p gang

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS