ShinyHunters exploits PeopleSoft zero day hole as FBI arrests suspected member
Hacking group ShinyHunters has exploited a new zero-day vulnerability in Oracle PeopleSoft while federal authorities have arrested a suspected member who is cooperating with law enforcement.
FTMQ Security, written by our newsroom1 view

Hacking group ShinyHunters has compromised Oracle PeopleSoft software by exploiting a new zero-day vulnerability, CSO Online reported. In response to the breach, security analysts recommend that enterprise customers take extreme measures, specifically pulling the Environment Management Hub and the Integration Broker completely off the public internet. [1]
Law enforcement authorities have made progress in their ongoing pursuit of the cyber criminals involved. CSO Online noted that Reuters reported on Saturday that the FBI arrested a suspected member of ShinyHunters. The arrested individual is cooperating with law enforcement to help identify additional members of the hacking group. [1]
ShinyHunters initial activities began with major breaches in 2020, which involved stealing 91 million records from Tokopedia and 271 million records from Wattpad through unsecured cloud storage and GitHub repositories. The group eventually expanded its operations into voice phishing tactics and enterprise cloud applications, claiming breaches against AT&T for 70 million records in 2022 and Pizza Hut Australia in 2023. [4]
PeopleSoft was originally founded on August 18, 1987, in Walnut Creek, California, before Oracle Corporation acquired it for $10.3 billion in 2005 following an extended hostile takeover attempt. Oracle has maintained development and continued support for the legacy human capital management product line in the decades following the merger. [5]
In short
- ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft.
- Analysts recommend disconnecting Environment Management Hub and Integration Broker from the public internet.
- The FBI arrested a suspected ShinyHunters member who is cooperating with law enforcement.
- Oracle acquired PeopleSoft for $10.3 billion in 2005.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]ShinyHunters’ exploitation of a new PeopleSoft zero-day hole threatens to change enterprise risk dynamicsCSO Online, 13h ago (the report this story comes from)
Background
- [2]QAnon on Wikipedia
- [3]Hole (band) on Wikipedia
- [4]ShinyHunters on Grokipedia
- [5]PeopleSoft on Grokipedia
Our newsroom writes these reports with the help of software, from the 5 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- Suspected ShinyHunters Hacker Detained in Jordan Cooperating With FBITop Stories, 1d ago
More in Top Stories
- OpenAI introduces invisible text watermarking for ChatGPT and Codex in EU14h ago
- Microsoft Patches High Severity Privilege Escalation Flaw in Exchange Server16h ago
- Hackers target Rejetto HFS servers following critical session forgery vulnerability discovery16h ago
- ClingSTUN Malware Compromises Unpatched IoT Devices as Proxy Nodes16h ago
- China Aligned TA419 Targets US AI Experts With Phishing Attacks1d ago
- Citrix issues emergency updates for NetScaler zero day vulnerability1d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.