A newly uncovered cyber campaign targeting Oracle PeopleSoft environments highlights a growing trend in cybercrime: attackers are increasingly targeting the software platforms that underpin critical organisational operations rather than individual users.
Researchers from Google Threat Intelligence Group (GTIG) and Mandiant have linked an active compromise and extortion campaign to the ShinyHunters cybercriminal group, which exploited a critical zero-day vulnerability in Oracle PeopleSoft before a patch became available. The activity was observed between late May and early June and primarily affected organisations in the United States, with higher education institutions accounting for the majority of identified targets.
According to the researchers, attackers leveraged a remote code execution vulnerability in the PeopleSoft Environment Management component, allowing them to gain access to enterprise resource planning environments responsible for managing finance, HR and operational systems.
The findings reinforce a growing concern among security professionals that enterprise management platforms have become attractive targets for financially motivated threat actors. Unlike ransomware attacks that focus on endpoint compromise, successful exploitation of ERP environments can provide access to vast stores of sensitive organisational data and critical business processes.
Researchers found the attackers deployed customised MeshCentral agents disguised as legitimate cloud infrastructure to establish persistence and execute administrative commands on compromised systems. The activity occurred before Oracle issued a formal security advisory, effectively making the attacks a zero-day campaign.
While the campaign focused heavily on education organisations, security experts warn the underlying risk extends far beyond the sector itself. Oracle PeopleSoft remains widely deployed across government agencies, healthcare providers, utilities and large enterprises globally.
The campaign also highlights the evolution of ShinyHunters. Historically associated with large-scale data theft and extortion operations, the group has increasingly demonstrated the ability to combine social engineering, cloud compromise and now software vulnerability exploitation as part of broader extortion strategies. Earlier this year, the group was linked to attacks against education technology provider Instructure and its Canvas learning platform.
For defenders, the incident serves as a reminder that vulnerability management remains a critical component of cyber resilience. While identity attacks continue to dominate headlines, threat actors remain quick to exploit exposed enterprise software when opportunities arise.
Security teams are being urged to identify any internet-facing PeopleSoft instances, apply Oracle’s security updates immediately and review systems for indicators of compromise associated with the campaign. The rapid weaponisation of newly discovered vulnerabilities demonstrates how little time organisations now have between disclosure and active exploitation.
As threat actors continue to seek high-value targets capable of delivering maximum leverage for extortion demands, enterprise application platforms are likely to remain firmly in the crosshairs.








