ShinyHunters, the gang behind some of the largest data thefts of recent years, claims to have broken into Oracle PeopleSoft servers at more than 100 organizations — universities prominent among them.
The group says it compromised PeopleSoft deployments across more than 100 institutions, with higher-education entities making up a notable share of the alleged victims. PeopleSoft is Oracle's enterprise platform for HR, payroll, and student records — exactly the kind of data that sells. ShinyHunters has a documented track record of following through: the gang was linked to the 2024 Ticketmaster breach that exposed data tied to hundreds of millions of customers, and it routinely monetizes stolen records on criminal forums. None of the claimed victims have confirmed a compromise.
The bigger concern is the platform-level scope. A campaign targeting a single enterprise product across more than 100 organizations is a multiplier attack — one vulnerability or credential type, exploited at scale. PeopleSoft's wide deployment in sectors slow to patch enterprise software makes it a recurring target, and universities in particular tend to run lean security operations relative to the volume of sensitive data they hold.
ShinyHunters has every incentive to oversell scale when marketing stolen data, so the claim warrants scrutiny. But given the group's recent history and PeopleSoft's age, treating this as noise looks like the riskier bet.
